Live data from Hacker News

'Impossible-to-hack' security turns out to be no security

jltee.substack.com

91–100 of 157 posts

Re: 'Impossible-to-hack' security turns out to be no security

#91

Earlier quoted context omitted.

I am in a very client facing role, and my clients quite like me. You know nothing about me, and you are completely misunderstanding this situation. I am holding the researcher accountable to how they comported themselves in this interaction instead of dick-riding a fellow hacker I actually do understand what security researchers usually want out of such an interaction. Where things fall apart is that the CEO does _no…

He is absolutely in his right to write a post about it. He even tried to mediate with a third party. You are delusional if you think somebody owes you something in that situation.

> I'm simply trying to say the researcher would have more pleasant interactions with the people they email if they helped the person understand what they _do_ want out of the interaction instead of just saying they aren't being scammed. If the researcher placed themselves in the shoes of the CEO, they could understand why the CEO responded that way. That's not the same thing as thinking the CEO _should_ have responded that way. I am also not letting the researcher off the hook for responding to the CEOs response the way they did.

Re: 'Impossible-to-hack' security turns out to be no security

#92
post #61

Earlier quoted context omitted.

The email that the author sends to the CEO, in which his rationale for immediate disclosure is the fact that the database was fixed.

To which the CEO was rude and dismissive and threatening. Which is often a sign of having something to hide. I assume the author decided to then verify if the threats were made from a position of strength or weakness. I read his email as a polite gesture, giving them a chance to request more time. I'm still confused as to what parts you're missing. Are you trying to imply something, or do you really not understand th…

Did you miss this bit from the article:

> The email was read by someone, I assume the CEO, and less than an hour after it was sent, I could not connect to the exposed server anymore.

This was after the author’s first email, and before the CEOs reply.

What tptacek was getting at is that the article is a bit unclear on when the review of DB contents occurred, since the author no longer had access. (But I think it’s just because the author reviewed the contents already before they reported the issue.)

Re: 'Impossible-to-hack' security turns out to be no security

#93

Earlier quoted context omitted.

He is absolutely in his right to write a post about it. He even tried to mediate with a third party. You are delusional if you think somebody owes you something in that situation.

> I'm simply trying to say the researcher would have more pleasant interactions with the people they email if they helped the person understand what they _do_ want out of the interaction instead of just saying they aren't being scammed. If the researcher placed themselves in the shoes of the CEO, they could understand why the CEO responded that way. That's not the same thing as thinking the CEO _should_ have responde…

You are right if you just look at the emails you are disregarding the attempt to mediate via a reputable third party. In which the ceo reacted in the same way.

Re: 'Impossible-to-hack' security turns out to be no security

#94
post #5

To be fair, security through denial, lies and intimidation is the industry standard. Leaving the passwords in clear text is double plus ungood. But my employer recently bought another outfit that does just that, and fixing it is not a near term option. So I'm stuck managing that and three of my fingers are pointing back to me.

Some powerful people subscribe to the idea that "if I (or the law) says don't touch it, it's secure". This attitude was on full display a little over three years ago in Missouri. https://missouriindependent.com/2021/10/14/missouri-governor...

That's a good one!

Reporter: "Hey, you dropped your wallet" Governor: "Thief!"

Re: 'Impossible-to-hack' security turns out to be no security

#95

Earlier quoted context omitted.

Sure you do. The poster was polite, got an extremely rude response, and has no obligation to be polite afterwards. Airing their shit out is a disclosure of a vulnerability, and it's important to do. Typically you reach out to say, "how would you prefer I do this?" And work through a common understanding. The company flipped the bird, so it got aired very publicly.

I can call myself a bicycle but I don't have any wheels. Their behavior when things don't go their way belies their initial "politeness". When the transaction didn't go how they wanted, they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email. If this were a coworker or a contractor, it would color all of my interactions with them going forward.

> they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email.

brain dead take; the article was impolite, the email was an overt threat by an impotent exec *in response to someone trying to help*!

Dang it bobby, it's not worse to respond to respond to asshattery (the email) with irreverent sunlight (the article).

I also wouldn't call you a bicycle because you're not going anywhere with this attitude. The CEO got a gift, and the author got a middle finger. No matter what happens after, the CEO without a doubt shot first. And shot someone just trying to help. He can get fucked, and anyone defending him can join in too.

Re: 'Impossible-to-hack' security turns out to be no security

#96

Earlier quoted context omitted.

> First of all, please do not ignore this email, this is not a scam attempt nor am I trying to sell anything, I am just alerting and looking for help closing down a security issue […] This seems like a good hint.

I can't tell if people are being deliberately dense as a way of punishing me for having a critical opinion, not reading the rest of the comments before responding to me, or genuinely do not understand what I am getting at. A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you. Humans famously have the capability of lying. Someone telling me they are _not_ selling…

>A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you.

The very first email has literally everything the company needs to locate and fix the issue without having to sign anything, log into anything, or pay anything.

That is the opposite of a nefarious email.

Nefarious "beg bounty" emails will tell you that you have an issue and then not tell you where it is -- asking for money before revealing the issue.

Re: 'Impossible-to-hack' security turns out to be no security

#97
post #71

Earlier quoted context omitted.

Does the CEO know what?

The motivations behind the researcher emailing them.

If my first email contains everything required for you to locate and fix your security issue, my motivations are pretty clear.

Re: 'Impossible-to-hack' security turns out to be no security

#98

Earlier quoted context omitted.

Agree. "You're not wrong, Walter, you're just an asshole!" Best case scenario, CEO just got an annoying distraction that was a credible enough threat they had to waste time investigating. Worst case they had a breach and someone is extorting or hacking them. Some grace on the part of the researcher is warranted IMO, despite the amateur handling by the CEO. No one looks good here.

The OP/researcher looks fine. They tried twice to help someone who would eventually prove they didn't deserve they help. They then, after being disrespected, still upheld all the ethical requirements from a security researcher, redacting sensitive information. The CEO looks like a twat waffle, but the researcher is clean, and just looks like someone intolerant of overt disrespect. Being willing to stand up to bullies…

I don't know how you could see the CEO as a bully in this situation. The researcher clearly has "power" in this situation over the CEO, he pretty much has caught him with his pants down, so in this case the CEO is lashing out at a perceived threat. You are entitled to the opinion that the researcher responded proportionately in this situation, I happen to disagree. I would not want my friends or coworkers responding this way in their daily dealings, I would want to give someone a chance to make amends instead of escalating, because this is not a playground and the stakes for the CEO are very real and potentially very damaging.

I hope maybe we can agree, though, that with a few simple modifications to his approach, he is likely to reduce the probability of negative responses to the initial email. For example, he seems to already understand that people will take this email as a scam or sales attempt. But much is left to the imagination of the (uninformed) recipient about what the auth truly _does_ want. By filling in those blanks, the imagination need not be active.

Re: 'Impossible-to-hack' security turns out to be no security

#99

Earlier quoted context omitted.

I can call myself a bicycle but I don't have any wheels. Their behavior when things don't go their way belies their initial "politeness". When the transaction didn't go how they wanted, they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email. If this were a coworker or a contractor, it would color all of my interactions with them going forward.

> they pulled the trigger on being a dick, publicly. That is a much worse offense that an impolite email. brain dead take; the article was impolite, the email was an overt threat by an impotent exec *in response to someone trying to help*! Dang it bobby, it's not worse to respond to respond to asshattery (the email) with irreverent sunlight (the article). I also wouldn't call you a bicycle because you're not going an…

I'm not defending him so much as advocating for understanding, grace, transparency, and de-escalation. You of course are welcome to conduct yourself in the ways that you see fit.

Re: 'Impossible-to-hack' security turns out to be no security

#100

Earlier quoted context omitted.

I see you read and understood the researcher's emails as well as the CEO did, then...I'm not assuming anything, I'm repeating what was said. Are you suggesting that lacking understanding of something someone says, one's first reaction should be an asshole to that person, just in case they are trying to sell something?

No, I'm simply trying to say the researcher would have more pleasant interactions with the people they email if they helped the person understand what they _do_ want out of the interaction instead of just saying they aren't being scammed. If the researcher placed themselves in the shoes of the CEO, they could understand why the CEO responded that way. That's not the same thing as thinking the CEO _should_ have respon…

The author did just that, though. They said they wanted to write up a post about the incident.

I think both I and the author understand why the CEO responded as they did; it's because the CEO doesn't care about security, and when a security issue was raised, they viewed the reporter as a threat to the blanket of lies they wanted to use to brush the whole thing under the rug.

In light of that, I think the author's response was appropriate. A lesser response would be letting the company off the hook.

Post reply on HN