6 ms·
I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy le
by goodplay 9y ago
I remember coming across a serious bug in a site that belonged to a top multi-billion company. My brother also found what essentially an unrestricted privacy leak (and possibly editing access) in a top university (leaked data is sensitive personal information, not academic). Neither of us reported (or exploited) what we found.
Protection from this kind of blame-shifting and misdirected retaliation should be guaranteed by law. Until it is, bugs in critical and important infrastructure will go on unreported, and remain available for malicious actors to exploit.
- warrenm 9y agoWhy didn't you report it? Seems somewhat negligent - at the very least from a Good Samaritan™ point of view
- Cerium 9y agoReporting these things can get you in trouble. Once burnt twice shy.
- Antrikshy 9y agoDid you not see the top post?
- JohnGB 9y agoIf he reported it, he runs the risk of the company turning on him (as was the case in the article above). If he doesn't report it, nothing happens. It's a choice between the certainty of no loss vs the possibility of great loss.
- kodfodrasz 9y agoIf he does not report it, and somebody else does, then he runs the risk of being rightfully accused of hacking, as the motivation can be understood as financially motivated.
- warrenm 9y agoBudapest != United States
- grrowl 9y agoYou're often opening up yourself to a LOT of bad exposure, where you'll be accused of hacking the software (along with the 20+ jail term this might eventually entail) and just generally putting the spotlight on yourself as a potentially dangerous person. Better to report anonymously, or report directly to someone who might appreciate or is responsible (and hope they appreciate responsible disclosure).
- skinnymuch 9y agoYou're replying to a comment about news of someone being arrested for a similar thing.
- warrenm 9y agoThere's such a thing as anonymous reporting
- skinnymuch 9y agoWhat if you don't do it anonymously enough? And they trace it back to you? Not that this has ever happened (I have no idea. I'm assuming not). But being paranoid isn't unwarranted either.
- patryn20 9y agoI was more naive, but it worked out. Reported a vulnerability and how to fix it to a regional bank when applying for a student loan. They asked me to come in person to explain it and dropped a point off my interest rate. In hindsight it was a huge risk and I was dangerously trusting.
- kpil 9y agoIf you are nice and don't threaten to publish, at least without giving them any time to fix it - which for a large back is a couple of months - then I don't think it's a risk at all. What they don't like is the publicity. Edit: but maybe not in Hungary. It's the bad child in EU.
- FRex 9y agoIn Poland there was a case few years back of a company (I have no idea if that means a one person company or a bigger one) owner finding out by putting a name of his client into google that it indexed documents containing private information of over a 1000 of companies that are clients of PKO BP and reported it to the bank. At first the bank security department said no one will find it so it's safe and later when he pressed the issue as a dangerous leak they reported him to the police for "hacking and extortion". All the computers from his company got confiscated for investigation so he had to buy new computers and software to continue running his company. In the end he was found not guilty by the police investigation of his computers so the prosecution dropped the case (it didn't even go to court) and all his stuff returned after 6 months. Source in Polish (sorry, there is no English source): https://niebezpiecznik.pl/post/glebokie-ukrycie-danych-w-pko-bp/ https://niebezpiecznik.pl/post/glebokie-ukrycie-danych-w-pko... http://www.tvn24.pl/wiadomosci-z-kraju,3/haker-mimo-woli,132992.html http://www.tvn24.pl/wiadomosci-z-kraju,3/haker-mimo-woli,132... Bank spokesperson later explained that the files were "deeply hidden" ("głębokie ukrycie", he said it's an IT term, it's not) and only one person found them in 4 years of their existence there so it's not a big deal. And in general misusing, testing, etc. a website is illegal without owners permission, there is now a small exception for acting in good faith but it's narrow, a bit strangely worded and it doesn't prevent stuff like above.
- Gustomaximus 9y agoI get where you coming from but I would still encourage people to report. Most companies will want to fix and hush it up. I have previously found a way to access very personal information in a large corporate billing system. When I contacted them I specifically used careful language that what I'd done was unintentional, and easy mistake that could lead others to this, that I kept zero data and exited the system as soon as I realised 'my mistake' and was very surprised. Basically enough that 1) If it should go to court the situation would be in my favour as much as it can be and 2) Given they were a well know public retailer I figured this would hit social media and make an uproar about the company should they act badly. Initially I contact several people in IT and heard nothing. Six months later when I noticed this was still open. I then contacted the CEO. Expecting nothing or canned 'thanks', we was thankful had some followup contact about the issue. I wont say there is no risk, but I think its the right thing to do and risk seems minimal. And you can always do it anonymously.
- qb45 9y ago> And you can always do it anonymously. Assuming you have done the hacking anonymously in the first place.
- etatoby 9y agoThat's yet another reason to run something like Qubes OS, split up your online presence into distinct "domains" and heavily firewall each domain, only connecting it through VPNs and/or Tor in most cases.
- DerpStar_K 9y agoBecause TOR is safe...
- Natanael_L 9y agoYeah, you have to consider if there might be logs likely showing you to be the only person to have used the system in the manner you described.
- 9y ago
- jogjayr 9y agoI'm having trouble understanding what exactly an org's thought process is when they elect to prosecute someone for reporting a security issue. Would they also prosecute a person who told them one of their doors was left unlocked after-hours? A normal person's reaction upon being told "You left your keys in the lock" is usually gratitude, not calling the cops. EDIT: Is it suspicion? "Hmm...this person found an unlocked door, which means they were clearly trying all the doors. Don't like that. Who knows what else they found but didn't report." Which is understandable, but clearly counter-productive. If the person was a malicious actor, they obviously wouldn't go to the trouble of reporting in the first place.
- emiliobumachar 9y agoThis. Executives who usually have no trouble treating engineers as replaceable parts, suddenly fail to believe someone else can and possibly has found the same vulnerability. They think getting rid of the one person capable of finding it is all it takes to be safe.
- pavanred 9y agoYou fear what you don't understand
- bigbugbag 9y agomaybe you're projecting your own ability to them, have you considered that maybe they are highly incompetent and do sincerely believe this was a cracking attempt on their system. Then again there is this culture of making an example to discourage others to even try, similar to prison, which we know is not that effective if at all.
- jasonzemos 9y agoNever underestimate the diversity of the concept of Justice in those who are uneducated, unwise, and dishonest to what is real. If you try to trace this behavior you'll find truly random causes. There are an infinite number of ideas one can substitute for something they don't know or willfully ignore in their own perceived interests. The real problem is when those substitutions are guiding determinations for someone with authority over others. I'll also add: when I was a teenager I've been in this position countless times, reporting security issues at school, etc. The reactions I received from fully grown adults was nothing short of stochastic. This fascinated me enough to minor in political science and philosophy/ethics. I draw on that for insight, but it doesn't really provide a final answer.
- posterboy 9y agoreport anonymously!?
- rtpg 9y agoI understand that it's good to have cover for this sort of thing. I think the line is pretty grey though. One analogy is telling a company that their front door is unlocked. Another analogy is going into an unlocked front door, and going deeper into the building, and then reporting to the company that you could, in fact, get to classified information from this door. IRL Pentesters get permission before trying to sneak into buildings, so there's some argument for it being the same for these sorts of things. EDIT: I 100% think that users that are acting in good faith shouldn't be thrown in prison. This case is a pretty good example of this
- alanfranzoni 9y agoWhen you test for a vulnerability, many times you don't know whether it actually works unless you go "deep into the building". In this situation, it would have been difficult to report the parameter tampering without verifying that it actually worked (there're systems that pass params back and forth without apparent use, but they throw an error when client and server states don't match) - and, most probably, the report would have been ignored without the verification.
- imhoguy 9y agoExactly. Often to validate the door is unlocked one needs to use the knob and open it a little - shall one get a permission for that just for a sake of a check. Is this already a breach to open the door without crossing the threshold?
- madaxe_again 9y agoI disagree. It's more akin to trying the handle on the door, and noticing it's unlocked, and then telling them, and being arrested for touching the door handle.
- loup-vaillant 9y agoNote: the nature of the reported vulnerability was such that the teenager didn't even have to access the servers to do it —only change a value that was sent by his own browser. If that was tantamount to not-breaking & entering, it means the it is okay to legally forbid step by step debugging on your own computer. That it may not be legal to inspect code from another company, even if it runs on your computer. That whatever the code decides (here, the price of the ticket), must be observed by the rest of the system (here, the price sent in the HTTP request wasn't the price decided by the web page). The consequences of such thinking are chilling. If this is the kind of cyberpunk we're heading to, I'll seriously consider becoming a Runner.
- loup-vaillant 9y agoMaybe they could use some threatening instead of a proper report. Go to a public spot, open up a Tor browser, then report the vulnerability. Something like this: "I have hacked your system, accessed <this information> and modified <that bit of data>, using <this procedure>. You have <this time> to send <this much> Bitcoins to <this wallet>, or I <copy or trash> your database. Thank you for your attention." Maybe they will panic strongly enough to actually do something about the issue.
- pfisch 9y agoSo you should just become a malicious actor and actually break the law? Good plan.
- Duplicated 9y agoWhat difference does it make if the outcome is the same?
- imhoguy 9y agoNot the outcome for the informer in case one gets caught and accused of threatening for ransom.
- loup-vaillant 9y agoBecoming a malicious actor, no. Looking like one, definitely. Break the law, most probably. Also, I would rather threaten to publish if I did this for real. It's risky and scary, but also the right thing to do in some cases. You could also fail to report at all, and let their ship sink. Maybe they deserved it.
- wlll 9y agoBetter hope you've not left any evidence on their systems then, you know, like a discounted transport pass.
- PeterisP 9y agoThat is quite straightforward and makes it clear from all perspectives. From the hacker "hat classification" perspective, that's obviously black hat, nothing gray about it. From the legal perspective it's not a debate anymore (like in the original article) if you do this, it's clearly a crime, if you get caught in whatever way (e.g. by bragging about it someplace later that leads to your person, or by testing a "discounted" pass in some place that has cameras), it's a straightforward conviction for extortion. From the ethical perspective, that is an unethical action, doing that shows that the person is immoral. But you are right, yes, it can be quite effective, and definitely makes it more likely that they will panic strongly enough to actually do something about the issue. It's just that if this happens, then it's not sufficient to just fix the hole, identifying and catching the perpetrator becomes a big part of what they should be doing.
- imhoguy 9y agoI have read some advice in the past that one should report vulnerabilties via officially known independent security related group (white hat) or via a journalist. The point is to get some legal backing just in case. Does anybody have an experience with such way?
- bondant 9y agoIn France, you can report vulnerabilities to the ANSSI (National Cybersecurity Agency of France). The agency stays somewhat neutral between justice and the company with vulnerabilities since ANSSI must protect confidentiality of their informer. Informations can be sent by email or postal service. http://www.ssi.gouv.fr/en-cas-dincident/vous-souhaitez-declarer-une-faille-de-securite-ou-une-vulnerabilite/ http://www.ssi.gouv.fr/en-cas-dincident/vous-souhaitez-decla...
- pyroinferno 9y agoI report all the vulnerabilities I find to the NSA. Very nice people.
- LunaSea 9y agoHad a similar issue with Wolfram Alpha some years ago. I reported a dozen different XSS vulnerabilities to them and their answer was: "We forwarded this email to our legal department.". So even technical companies can react in really silly ways.
- enraged_camel 9y agoI think legal's involvement is perfectly normal. Part of damage control consists of figuring out the legal ramifications of the product/service having technical vulnerabilities. Especially if those vulnerabilities leak customer data. What isn't cool is legal deciding to go after the party disclosing the vulnerability.
- kidmenot 9y agoNot having much experience on this subject, I have to ask: would you not get your developers to verify that the vulnerability is there and fix it while the legal department is doing its thing? The vulnerability is already out there, and the sooner it's fixed the better. While would they forward everything to their lawyers first thing?
- tzs 9y agoIf the email contains code or something that looks like code, or otherwise looks like it is discussing technical things it is not unusual to run it through legal before letting any engineers see it. That's because companies routine receive unsolicited product proposals, ideas for new features or enhancements, and the like. Often these overlap with things they have been working on internally but that are not known to the public. If they let engineers see these unsolicited mails and then later come out with an even vaguely similar feature they may find themselves in an intellectual property dispute with the emailer.
- kidmenot 9y agoAw gee, that makes sense, yes. Never worked for a company big enough to need this. Also, I'm in Italy, so some things might work differently here.