6 ms·
Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
- TealTigerAI 4mo ago[flagged]
- ryanisnan 5mo agoYikes, Schemata and that delinquent CEO should be held accountable.
- DougN7 5mo agoWould it be possible to stop using aXXb nomenclature within the titles? Some of us aren't hip enough to know what all of them mean.
- bearsyankees 5mo agoapologies, just a vc firm
- tomhow 5mo agoThe guidelines require using the same title on HN as is on the original post.
- tptacek 5mo agoEven when the author submits? :)
- tomhow 5mo agoYes... unless we think it's fine to tailor a title to activate a particular reaction from the HN audience :)
- bearsyankees 5mo agooh apologies, thanks for the reminder
- beambot 5mo agoAndreessen-Horowitz, who most people (and they themselves) refer to as a16z and have the eponymous domain name (a16z.com). They're one of the top VC firms on the planet -- exceedingly relevant to HN audiences and commonly discussed here.
- DougN7 5mo agoI'll be honest - I was thinking authorization (a11n?) - so I didn't read it closely enough. But despite that, and being on HN from almost the beginning (with a different account I lost the password to), I still didn't know what a16z was, though I do recognize Andreessen-Horowitz.
- Semaphor 5mo agoOpposite for me, I've seen a16z tons of time on HN, and also the domain where sometimes, but the full name would have meant nothing to me.
- rectang 5mo agoI didn't either. This is an ancient debate that can never be resolved completely, though — because the articles that HN submissions point to don't follow a style guide and there are always assumptions about audience priors. Best to just resolve it and move on.
- deleted 5mo ago[deleted]
- krisoft 5mo ago> you'd rather say Andreessen-Horowitz, which is just as arbitrary as a16z Yes. I know Andreessen-Horowitz and I don’t know a16z. Reading the title i thought it will be about the cryptography serialisation specification. Turns out i was mixing it up with ASN.1. > Their website is literally a16z.com I hear now. Before this if pressed i would have guessed that they probably have a website indeed. If you would have twisted my arm my guess would have been andersenhorovitz.com (yup, with the typos. I learned the correct spelling today from your comment.) > exceedingly relevant for the HN audience We contain multitudes.
- rectang 5mo agoa16z = "Andreessen Horowitz", for those not in the know. (The acronym is not expanded in the article. EDIT: OP has fixed the article.)
- bearsyankees 5mo agofixed now
- rectang 5mo agoThanks! Happy to have my comment hidden by the mods if they get around to it.
- bearsyankees 5mo agoappreciate the feedback!!
- cheschire 5mo agoPerhaps the community could band together and crowdsource the moderation action through flags. Kidding.
- OsrsNeedsf2P 5mo agoHonestly, I didn't know who Andreessen Horowitz was, until you spelt out a16z
- bearsyankees 5mo agohttps://x.com/strix_ai/status/2051361018450948511 https://x.com/strix_ai/status/2051361018450948511
- bryancoxwell 5mo ago> Their initial reply from the CEO: "I would love to hear what the vulnerability is, but I assume you want to get paid for it. Is that the play?" Well that’s pretty damning.
- tencentshill 5mo agoThey could sell the next one to an adversary for a lot more money if they're going to act like that.
- deleted 5mo ago[deleted]
- lixtra 5mo agoYes, there are also many other lucrative illegal activities.
- tardedmeme 5mo agoIsn't it also illegal to withhold knowledge of a vulnerability for payment? It sounds like it should fall under some variety of blackmail.
- mtlynch 5mo agoThat would be even worse than our already bad system. The system is already pretty bad because vendors underinvest in security, and then to fix it, researchers have to volunteer their time to investigate with no guarantee of payment. If the vendor could force researchers to hand over findings for free, nobody would want to do security research except hobbyists having fun. They're basically signing up for hours of tedious forced labor to explain vulnerabilities to the vendor. I wish there was legislation that allowed the government to fine vendors for security vulnerabilities like this where the amount scales based on how much user data they leaked. And it could function like other whistleblower systems where a researcher who spots a leak can report it to the government and collect 50%. That way, if the vendor says, "We're not paying you," the researcher can turn around and collect the money from fines.
- janice1999 5mo agoFinally the AI security startup hustlers will keep the other tech startup hustlers in line. Maybe the era of devastating leaks and total disregard for user privacy will come to an end (doubtful).
- bearsyankees 5mo ago[flagged]
- SkyGuard_Lead 5mo agoWait until we understand the depth of the current Mythos zero day situation. We already have an overall idea of what’s to come but I don’t think we can grasp the high level implications the vast array of these vulnerabilities have in store for us. I don’t see/ say this in a doomsday-ish way nor the world coming to an end. It will sting a bit but overall it’s way overdue and spells opportunity for all, imo.
- giannicmptr1000 5mo agoit won't end at mythos, that's just the one everyone knows about and obvious. think of what's going on behind the scenes, that's the real gold rush
- codegeek 5mo ago"There was no meaningful organization scoping, no tenant isolation, and no permission check preventing a low-privilege user from accessing other organizations' records." Let me guess though. They are SOC2 and ISO compliant right ?
- sailfast 5mo agoOne hopes not as this stuff would have come up in even a cursory audit of the product - but it’s kinda like Ratings Agencies / Moody’s in 2008 right now until a big breach that occurs post-cert and they lose their credibility.
- zbentley 5mo agoThe number of FISMA-HIGH, ATO’d/RMF’d, security audited government systems I’ve seen with equivalent security issues is…substantially nonzero. I have come to believe that most security audits, even ones conducted through widely-reputed groups or under strict standards, are much worse than useless. Audits are a thing that can theoretically be done well/in a value-adding way, but rarely are, for the same reasons that most private-sector security teams I’ve worked with are effective only at generating internal badwill, and ineffective at increasing security above a very low baseline.
- moron4hire 5mo agoI've been trying to figure out what exactly or IT Security Team does. Because all they seem to do is create stupid impediments that actually push people into making work arounds that make everything less secure. For example, they won't create for me an MS Entra ID App Registration for our internal project Because Security Reasons (they literally won't tell me why). So instead, I use Integrated Windows Authentication, which is about as secure as a hotel bar patron charging to "his" room. They are insisting everyone start RDPing into a VM in Azure to do development work. Won't be able to get to the new source control system without it. Old system is losing its license, etc, etc. Oh, but the new system is not approved for storing CUI. So... what the actual fuck are our AFSIM developers supposed to do? These VMs are 1/4 the hardware specs of my laptop in almost every dimension, yet still somehow car 50% more to rent per year than the entire purchase price of my laptop. Plus they are timesharing is in them, 4 developers per VM. It's not like we live in majorly different timezones. We're either all going to be on from 9am - 5pm EST or we're not. Within these VMs, I have absolutely zero ability to install any software or modify any settings. Even the god damn clock is set to GMT+0 and I can't change it to local time. Sure would be nice if the must visible clock in my visual field accurately portrayed the current time when I have the RDP session running full screen, which is basically the only way to run it without wanting to hammer drill my brains out. I have heard rumors that a lot of the other developers have started working from their personal devices, because otherwise they are at a complete work stoppage on their work computers due to the cockamamie IT setup. So congratulations, IT Security Team. Good job. I still want to know why--when we're wanting to run services like Document Intelligence and Azure OpenAI in Azure GCC High, a FedRAMP-High approved environment with these services claiming DoD Impact Level 5 compliance--our IT Security department thinks that can't be used for CUI. They say we need to spend 2 years and $2 million doing some kind of review of Azure itself before it can be approved for CUI. Uhm, no? If it needs that, why would we spend that money and time? Why wouldn't Microsoft be the one to do that?
- tardedmeme 5mo agoI wonder if this is how Handala group recently stole the list of service members. How do people find these vulnerabilities within the immense scope of the whole internet? Are they going around with some kind of generic API scanner that discovers APIs?
- yellowapple 5mo agoProbably based on insider info to some degree; if you already do any sort of work for the DoD, then that tends to help narrow the scope of the search for vulnerable things to exploit.
- fragmede 5mo agoYes. http://shodan.io http://shodan.io
- tptacek 5mo agoInitial take: as vulnerability stories go, this is a pretty boring one; what they have here is a target that was secured largely by the fact that few people knew about it. The most work done in this blog post is establishing that a training platform deployed by DoD might be much more sensitive than the same kinds of applications which are ubiquitous throughout corporate America and which are generally boring targets. The vulnerability itself appears to be something anyone with mitmproxy would have spotted within minutes of looking at the platform; apparently, rotating object IDs worked everywhere in the app, and there was no meaningful authz. It's interesting if AI systems can "spot" these, in the sense of autonomously exercising the application and "understanding" obvious failed authz check patterns. But it's a "hm, ok, sure" kind of interesting.
- skinfaxi 4mo ago> It's interesting if AI systems can "spot" these, in the sense of autonomously exercising the application and "understanding" obvious failed authz check patterns. But it's a "hm, ok, sure" kind of interesting. I think that misses the bigger point: automated scanners have gotten better and the floor for issues has risen. Security@ mailing groups are going to be getting more messages that aren't just noise from people running automated scanners.
- neilv 5mo agoTwo questions prompted by this disclosure: 1. I didn't see mention of a bug bounty program giving limited authorization. How do independent researchers do this with legal safety? Especially when DoD is involved? 2. If a researcher discovered a vulnerability at a DoD contractor, and the contractor didn't seem to be resolving the problem, is there a DoD contact point that would be effective and safe for the researcher to report it?
- antonymoose 5mo ago> How do independent researchers do this with legal safety? In my experience it’s usually foreign nationals from third-world countries doing drive-by beg-bounty testing. Presumably they don’t much consider legality.
- bornfreddy 5mo ago> Presumably they don’t much consider legality. Or the operation is not even illegal where they come from?
- orthogonal_cube 5mo agoTo answer the first question, a number of veteran independent researchers probably wouldn’t have touched such a system. Plenty of companies will send their lawyers after you if you tell them that you’ve discovered a vulnerability of some sort and wish to responsibly disclose. Even if you do things in good faith, the company has zero reason to assume the best from you and can hold a sword over your head by citing poorly-written laws that lean in their favor regarding computer fraud and abuse. DoD does appear to offer a “Defense Industrial Base - Vulnerability Disclosure Program” for all public-facing DoD/DoW systems.[1] However, this might not include contractor-controlled assets or services. I cannot view the HackerOne page that it redirects to (login is required) to view more details. [1]: https://www.dc3.mil/Missions/Vulnerability-Disclosure/DIB-Vulnerability-Disclosure-Program/ https://www.dc3.mil/Missions/Vulnerability-Disclosure/DIB-Vu...
- ungreased0675 5mo ago
- icedchai 5mo agoWas the app vibe coded?
- sailfast 5mo agoWould be fascinated to know if this went through competitive procurement or if it was one of those Hegseth “let’s be lethal and ship broken shit to the warfighter” procurements.
- mcoliver 5mo agoI've seen this at so many startups (and worked to patch the gaps and put in best practices) including those backed by top tier VCs. The problem is that it is rare for startups to have security minded people. It's usually designers, people who can raise money, and generalists who can stitch together apis. It's not generally platform, db, or security minded people. The proliferation of things like vercel and supabase have exacerbated this. So you get people deploying API keys client side and dbs without rls. Or deploying service keys client side when they should be anon. I mean really basic stuff.
- BowBun 5mo agoYep, this has been my experience over 15 years in startups as well. There are barely any punishments, so there is no incentive for startups to change how they operate.
- cyanydeez 5mo agoYou could even say they're paid even more to "move fast and break things".
- bigfatkitten 5mo agoWhile simultaneously wondering why software development being treated as a discipline of engineering is such a controversial subject.
- miki123211 5mo agoBecause, unlike bridges, software can easily be bought, including from countries that don't have such regulations.
- gnz11 4mo agoGovernments can certainly regulate imports.
- testing_auth 5mo ago[dead]
- SkyGuard_Lead 5mo ago[flagged]
- stephbook 5mo agoTenant scoping is important. Just ask Microsoft, didn't they have one right at bing.com? Oh, just every Bing user is vulnerable to have all Microsoft data (o365 emails for example) hacked. No biggie. https://www.wiz.io/blog/azure-active-directory-bing-misconfiguration https://www.wiz.io/blog/azure-active-directory-bing-misconfi...
- BobbyTables2 5mo agoFeels like they were too nice. After 90 days of no response, why not just go full disclosure on them? The CEO seems more interested in insulting people than securing his company’s product.
- luminati 5mo agooff-topic, but I've become quite intrigued with AI pentesting, after being very unhappy with the various pentest firms we've used in the past, that rip us off or do very mediocre tests (of course yeah yeah the really good ones exist but even then they're not going to match the speed at which we are claude coding now). Tried a bunch of open source pentesters, including strix (though we never managed to get strix to actually complete.) this project called shannon was the only one that we managed to get working reliably and it definitely smoked the output of one of the $10K pentests we did, (we had just discovered shannon after we had gotten the pentest firm's report, so it gave us a good baseline comparison). caveat: this was white box and our pentest firm did greybox, but neverthless I was still very unimpressed by what I got from the pentest firm. $50 vs $10K is not even a comparison lol with far far better results and sent our cto into near heart attack mode. i think the days of pentesting firms are over - especially with mythos/5.5-cyber etc like capability coming into play. very exciting times ahead!
- GhostDriftInc 5mo ago[flagged]
- vorsken 4mo ago[dead]