Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gibsonsecurity
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
Breaking International Voicemail Security via VVM Exploitation
(shubh.am)
3 points
by
gibsonsecurity
12y ago
|
1 comments
2.
▲
by
gibsonsecurity
13y ago
They won't see a huge amount of users deleting accounts, but I'm sure future users will think twice before joining. Also, the value of the company.
3.
▲
by
gibsonsecurity
13y ago
This isn't an issue with convenience, this is an issue with Snapchat failing to fix a vulnerability. How relevant is find_friends to Snapchat now? Is it really needed? Are they getting that many users building relationships for it? Is
4.
▲
by
gibsonsecurity
13y ago
We're going to be releasing a statement shortly. Here: https://gist.github.com/anonymous/8231005
5.
▲
by
gibsonsecurity
13y ago
For the record we don't know about SnapchatDB. But it was a matter of time until this happened, the exploit still works with minor modifications, you just have to be smart about it.
6.
▲
by
gibsonsecurity
13y ago
We don't :) (but we'd be happy to take Snapchats money and help them out!) We documented two exploits, which are exploits, because we are exploiting code that has been incorrectly implemented. We also noted that Snapchat must ha
7.
▲
by
gibsonsecurity
13y ago
Sorry about that - I thought it was clear from the context of those off-the-cuff estimations that it was 6666 numbers (since that was based off of how many numbers you could scan, not users). We've added some clarification just to be s
8.
▲
by
gibsonsecurity
13y ago
He isn't? Sorry that really is a mistake on my part. I thought I saw his name attached to it. I'm probably thinking of someone else, again I apologize to all parties involved.
9.
▲
by
gibsonsecurity
13y ago
Obvious privacy reasons that would probably get Snapchat sued, but otherwise, yes that would probably work.
10.
▲
by
gibsonsecurity
13y ago
We thought about that, and it would be pretty misleading. If they did find out data that way, they should really tell people how inaccurate it can be.
11.
▲
by
gibsonsecurity
13y ago
Definitely, lol. That's a pretty sneaky idea, I'm sure its possible with all the clients now available!
12.
▲
by
gibsonsecurity
13y ago
Hahahaha, I don't think making it harder to reverse would be any better, it would probably motivate people even more (deobfuscation is too much fun and fairly easy!). They should really just focus on improving what they have and pushin
13.
▲
by
gibsonsecurity
13y ago
I'm quite the fan of Steve Gibson, infact I use grsec on my boxes, sadly we only noticed this after our initial release, when it really was too late. If Steve Gibson hears of this, or reads this, my apologies, this was not intended. (a
14.
▲
by
gibsonsecurity
13y ago
Thanks, and that's totally fine. I agree with you, Snapchats definitely flawed from the start, but as long as we get rid of gaping holes in their security such as the find_friends exploit, at least they're halfway there. (OT, but
15.
▲
by
gibsonsecurity
13y ago
Hi, I'm one of the authors of the above release [1], and the exploit we primarily talked about (find_friends) isn't really an issue with the protocol as a whole. We understand the need to support legacy clients, but Snapchat coul
16.
▲
Snapchat Exploits and API documentation
(gibsonsec.org)
4 points
by
gibsonsecurity
13y ago
|
0 comments