Earlier quoted context omitted.
I am in a very client facing role, and my clients quite like me. You know nothing about me, and you are completely misunderstanding this situation. I am holding the researcher accountable to how they comported themselves in this interaction instead of dick-riding a fellow hacker I actually do understand what security researchers usually want out of such an interaction. Where things fall apart is that the CEO does _no…
He is absolutely in his right to write a post about it. He even tried to mediate with a third party. You are delusional if you think somebody owes you something in that situation.
'Impossible-to-hack' security turns out to be no security
91–100 of 157 posts
Re: 'Impossible-to-hack' security turns out to be no security
#92Earlier quoted context omitted.
The email that the author sends to the CEO, in which his rationale for immediate disclosure is the fact that the database was fixed.
To which the CEO was rude and dismissive and threatening. Which is often a sign of having something to hide. I assume the author decided to then verify if the threats were made from a position of strength or weakness. I read his email as a polite gesture, giving them a chance to request more time. I'm still confused as to what parts you're missing. Are you trying to imply something, or do you really not understand th…
> The email was read by someone, I assume the CEO, and less than an hour after it was sent, I could not connect to the exposed server anymore.
This was after the author’s first email, and before the CEOs reply.
What tptacek was getting at is that the article is a bit unclear on when the review of DB contents occurred, since the author no longer had access. (But I think it’s just because the author reviewed the contents already before they reported the issue.)
Re: 'Impossible-to-hack' security turns out to be no security
#93Earlier quoted context omitted.
He is absolutely in his right to write a post about it. He even tried to mediate with a third party. You are delusional if you think somebody owes you something in that situation.
> I'm simply trying to say the researcher would have more pleasant interactions with the people they email if they helped the person understand what they _do_ want out of the interaction instead of just saying they aren't being scammed. If the researcher placed themselves in the shoes of the CEO, they could understand why the CEO responded that way. That's not the same thing as thinking the CEO _should_ have responde…
Re: 'Impossible-to-hack' security turns out to be no security
#94To be fair, security through denial, lies and intimidation is the industry standard. Leaving the passwords in clear text is double plus ungood. But my employer recently bought another outfit that does just that, and fixing it is not a near term option. So I'm stuck managing that and three of my fingers are pointing back to me.
Some powerful people subscribe to the idea that "if I (or the law) says don't touch it, it's secure". This attitude was on full display a little over three years ago in Missouri. https://missouriindependent.com/2021/10/14/missouri-governor...
Reporter: "Hey, you dropped your wallet" Governor: "Thief!"
Re: 'Impossible-to-hack' security turns out to be no security
#95Earlier quoted context omitted.
Sure you do. The poster was polite, got an extremely rude response, and has no obligation to be polite afterwards. Airing their shit out is a disclosure of a vulnerability, and it's important to do. Typically you reach out to say, "how would you prefer I do this?" And work through a common understanding. The company flipped the bird, so it got aired very publicly.
I can call myself a bicycle but I don't have any wheels. Their behavior when things don't go their way belies their initial "politeness". When the transaction didn't go how they wanted, they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email. If this were a coworker or a contractor, it would color all of my interactions with them going forward.
brain dead take; the article was impolite, the email was an overt threat by an impotent exec *in response to someone trying to help*!
Dang it bobby, it's not worse to respond to respond to asshattery (the email) with irreverent sunlight (the article).
I also wouldn't call you a bicycle because you're not going anywhere with this attitude. The CEO got a gift, and the author got a middle finger. No matter what happens after, the CEO without a doubt shot first. And shot someone just trying to help. He can get fucked, and anyone defending him can join in too.
Re: 'Impossible-to-hack' security turns out to be no security
#96Earlier quoted context omitted.
> First of all, please do not ignore this email, this is not a scam attempt nor am I trying to sell anything, I am just alerting and looking for help closing down a security issue […] This seems like a good hint.
I can't tell if people are being deliberately dense as a way of punishing me for having a critical opinion, not reading the rest of the comments before responding to me, or genuinely do not understand what I am getting at. A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you. Humans famously have the capability of lying. Someone telling me they are _not_ selling…
The very first email has literally everything the company needs to locate and fix the issue without having to sign anything, log into anything, or pay anything.
That is the opposite of a nefarious email.
Nefarious "beg bounty" emails will tell you that you have an issue and then not tell you where it is -- asking for money before revealing the issue.
Re: 'Impossible-to-hack' security turns out to be no security
#97Re: 'Impossible-to-hack' security turns out to be no security
#98Earlier quoted context omitted.
Agree. "You're not wrong, Walter, you're just an asshole!" Best case scenario, CEO just got an annoying distraction that was a credible enough threat they had to waste time investigating. Worst case they had a breach and someone is extorting or hacking them. Some grace on the part of the researcher is warranted IMO, despite the amateur handling by the CEO. No one looks good here.
The OP/researcher looks fine. They tried twice to help someone who would eventually prove they didn't deserve they help. They then, after being disrespected, still upheld all the ethical requirements from a security researcher, redacting sensitive information. The CEO looks like a twat waffle, but the researcher is clean, and just looks like someone intolerant of overt disrespect. Being willing to stand up to bullies…
I hope maybe we can agree, though, that with a few simple modifications to his approach, he is likely to reduce the probability of negative responses to the initial email. For example, he seems to already understand that people will take this email as a scam or sales attempt. But much is left to the imagination of the (uninformed) recipient about what the auth truly _does_ want. By filling in those blanks, the imagination need not be active.
Re: 'Impossible-to-hack' security turns out to be no security
#99Earlier quoted context omitted.
I can call myself a bicycle but I don't have any wheels. Their behavior when things don't go their way belies their initial "politeness". When the transaction didn't go how they wanted, they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email. If this were a coworker or a contractor, it would color all of my interactions with them going forward.
> they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email. brain dead take; the article was impolite, the email was an overt threat by an impotent exec *in response to someone trying to help*! Dang it bobby, it's not worse to respond to respond to asshattery (the email) with irreverent sunlight (the article). I also wouldn't call you a bicycle because you're not going an…
Re: 'Impossible-to-hack' security turns out to be no security
#100Earlier quoted context omitted.
I see you read and understood the researcher's emails as well as the CEO did, then...I'm not assuming anything, I'm repeating what was said. Are you suggesting that lacking understanding of something someone says, one's first reaction should be an asshole to that person, just in case they are trying to sell something?
No, I'm simply trying to say the researcher would have more pleasant interactions with the people they email if they helped the person understand what they _do_ want out of the interaction instead of just saying they aren't being scammed. If the researcher placed themselves in the shoes of the CEO, they could understand why the CEO responded that way. That's not the same thing as thinking the CEO _should_ have respon…
I think both I and the author understand why the CEO responded as they did; it's because the CEO doesn't care about security, and when a security issue was raised, they viewed the reporter as a threat to the blanket of lies they wanted to use to brush the whole thing under the rug.
In light of that, I think the author's response was appropriate. A lesser response would be letting the company off the hook.