11 ms·
List of Y Combinator companies I have worked with (hacked)
- andrea_s 11y agoAmbiguity clickbait is the best clickbait :-)
- introvertmac 11y agosorry, what do you mean ?
- JD557 11y agoI believe you are referring to the original title: "List of Y Combinator companies I have worked with(hacked)" (I had the same feeling when I opened the page). However, the author is a security researcher and has indeed hacked (as in, disclosed vulnerabilities) the companies in question, so I thing the title is not ambiguous.
- introvertmac 11y agoYes, That's what I did. Thanks for understanding.
- deleted 11y ago[deleted]
- onion2k 11y agoThis is awesome, and exactly the right way to go about things (reporting things privately, telling people when there's a good outcome). It's good to see so many HN companies handling their side of the issues so well too. EDIT: Just for curiosity's sake, how many HN companies have you tried to hack? 24 successes (not counting HN as a company) out of every company that's been through the accelerator would indicate HN companies are unusually good at websec. Conversely, if you've only tried to hack 24 and you've had 24 successes, that would indicate something else.
- introvertmac 11y agoMost of the companies do care about their security, and they handle every email with proper attention. And yes YC companies are best to work with
- introvertmac 11y agoI was targeting YC company, I just filtered my success with YC companies. With bug bounties there are many cases of duplicate issues or they are aware of issue internally. That count as failure for me but not to the companies.
- jonah 11y agoHow many did you attempt to hack total and how many did you not succeed at?
- introvertmac 11y agodo not remember the ratio, but sometime it was easy some it wasn't. As I test only website, most companies do test their sites themself. So you can consider 70-30 ratio for success-failure
- fulafel 11y agoShame to see them being so thrifty about rewards though. At least the ones that could well afford better. (Or maybe he explicitly asked only for t-shirts?)
- introvertmac 11y agoYes, I wrote. I was a jerk. Now when I do have 60+ i don't even care.
- introvertmac 11y agoBTW "when you are good at something, never do it for free". So I don't ask for T-shirt, only work for paid work.
- ibnudaruaji 11y agoNow HN has free advertisement section? :^)
- introvertmac 11y agoHave you read the blog post ?
- ibnudaruaji 11y ago> ... want to hire me ? not a promotion, huh?
- introvertmac 11y agoyou haven't read, i wrote "croud sourcing" is best !
- nitrogen 11y agoHN visitors have a long and glorious tradition of self promotion.
- introvertmac 11y agoyou are right.
- atmosx 11y agoI thought about it before getting to the bottom... So it made sense.
- deleted 11y ago[deleted]
- introvertmac 11y agoyes, people make assumptions before reading thing.
- Uptrenda 11y agoWhat kinds of vulnerabilities did you find?
- introvertmac 11y agoSecurity Bugs. OWASP TOP 10 mostly
- voltagex_ 11y agoDoes YCombinator have someone to advise on basic security issues like this?
- introvertmac 11y agoI guess No, better ask @Sama. Hopefully you'll take my name :)
- raju64522 11y agoI would like to share the information to get jobs easily <a herf="http://hadooptraininginhyderabad.co.in/informatica-training-in-hyderabad/">informatica http://hadooptraininginhyderabad.co.in/informatica-training-... online training</a>
- introvertmac 11y agowow, that's what we call spamming :P
- Tepix 11y agoI signed up for the Firebase beta in February 2013 using a unique email address and got a phishing mail to that address in September 2013. I reported this fact to security@firebase.com but never got a reply. I guess they preferred to sweep the theft of their customer database under the carpet.
- introvertmac 11y agoare you sure that was phishing mail ?
- Tepix 11y agoIt was a pretty much standard phishing mail pretending to be from paypal (but sent from GMX), so yes.
- introvertmac 11y agoYou did the right thing by reporting the link.
- kalleboo 11y agoWe once used a third-party service (the name eludes me now) to handle our customer mailing list, and of course they got hacked, so everyone who used unique email address + extensions blamed us for selling their addresses to spammers. They only acknowledged the hack in a "we're investigating this"-type blog post, and 6 months laters they revamped their blog and the post mysteriously disappeared...
- deleted 11y ago[deleted]
- Tepix 11y agoDid you alert your customers? Firebase didn't and they were bought by Google a year later, so sitting it out appears to have been the right thing (from their point of view).
- willthames 11y agoI found a bug in your page! The link to the Gitlab acknowledgements page isn't right (not sure what the correct link should be). Let me know what my bounty will be ;)
- introvertmac 11y agohaha, is that a security issue ? this is the link https://about.gitlab.com/vulnerability-acknowledgements/ https://about.gitlab.com/vulnerability-acknowledgements/ BTW you can have free invisible hug and a big thank you :)
- mod 11y agoWow, you pay as well as half of these startups.
- introvertmac 11y agohaha, I don't have money because of these startups so..
- Pizzalover 11y agoT-shirts, t-shirts, t-shirts...pathetic.
- Sir_Cmpwn 11y agoI looked at your nod on the HN page: https://news.ycombinator.com/security.html https://news.ycombinator.com/security.html >The site name display for stories was vulnerable to an IDN homograph attack. How is that sort of thing mitigated?
- dsr_ 11y agoThe general case is that you are taking input from an untrusted source and later displaying it. You need to do two things: validate that it is the kind of data you are expecting, and scrub it of entities that might be a problem. You can't do either one of these on the browser side because a bad actor can pretend to be your code and submit it without the checks. (For good clients, you can run a check that prevents them from making simple mistakes. You can't trust that, though.) Validating that you have a correctly formatted URL is not too hard. You can even request the URL to make sure that it's reachable. But that doesn't tell you anything about the content, because evil people can't be trusted to turn on the evil flag in their packets. The safest case is to drop all submissions with IDNs; the next safest is to compile a list of homographs and drop anything with those; after that, you might keep a blacklist (which, unfortunately, can grow without reasonable bounds). You can outsource the blacklisting to centralized services checked via HTTPS API or DNS RBL or...
- pfg 11y agoEither block them entirely or use Punycode[1] when displaying IDNs. [1]: https://en.wikipedia.org/wiki/Punycode https://en.wikipedia.org/wiki/Punycode
- sctb 11y agoYes, we now use Punycode.
- zappo2938 11y agoTIL what a homograph attack is. [1] Thanks. 1. https://en.wikipedia.org/wiki/IDN_homograph_attack https://en.wikipedia.org/wiki/IDN_homograph_attack
- introvertmac 11y agoyou got it :)
- ejcx 11y agoI did my first conference talk[0] on this, and also have a similar list. Security consulting is expensive and the value just isn't there at all for early stage companies. It's why I think Owasp top 10 should be required reading for founders. As for my conference talk, the delivery was atrocious (warning if you choose to watch). I spent 5 minutes per startup and churned through hundreds. I didn't name names because there were too many bugs to report after a day or two of doing it. [0] - https://www.youtube.com/watch?v=wzrVYyouQTk https://www.youtube.com/watch?v=wzrVYyouQTk
- introvertmac 11y agoyou do mobile as well ?
- ejcx 11y agoI can break mobile apps too, but my workflow is less pretty for churning through a hundred companies, so didn't do anything mobile for the talk. The talk was 100% web based
- introvertmac 11y agoI'm looking for some resources to start with mobile, can you suggest some ?
- dsacco 11y agoThe Mobile Application Hacker's Handbook covers both iOS and Android very well. Give it a try.
- introvertmac 11y agoHopefully, I'll get it as gift by reporting some bugs to their site.
- misiti3780 11y agolink to docs: https://www.owasp.org/index.php/Top10#OWASP_Top_10_for_2013 https://www.owasp.org/index.php/Top10#OWASP_Top_10_for_2013
- hellbanner 11y agoWow, I'm amazed how many companies I recognize and/or use were in YC.
- introvertmac 11y ago800 companies got funded till date.
- deleted 11y ago[deleted]
- introvertmac 11y agoMost of them are early stage, most of them just can't trust a random email,Some of them want to save money for facebook ADs. That's how startups work these days.
- tonomics 11y agoAre they better for corporations and larger companies?
- introvertmac 11y agolarger companies like Oracle,Adobe hardly give a damn. Sometime they say "Thanks" that's it
- meowface 11y agoI don't think anything he found could come close to bankrupting any of the companies... but I agree he should be receiving a more significant award, even if the companies don't have a bug bounty program yet.
- aagat 11y agoAre you Nepali/of Nepali origin? It's great to see a (possible) compatriot featured in 1st page of HN for hacking HN. The reward does seem a bit thrifty as others have pointed out. Keep up the good work.
- introvertmac 11y agoNo I'm Indian, I live a bit close to Nepal(Bihar) but am not Nepali.
- aagat 11y agoOh haha. Your surname is common one in Kathmandu and uncommon one outside the valley. I guess it's more widespread that I think lol
- introvertmac 11y agoYa, Indians are everywhere. Nepal is our second home.
- aagat 11y agoWell there are billion Indians, so it's no a surprise. Just bring your own supplies if you are visiting and you should be alright. It's not like we can be of any help regarding that :-P
- armabiz 11y agoDear %username%, thanks for reporting this critical security vulnerability, affecting our multi-million business. Do you want a T-shirt?
- introvertmac 11y agoHaha, for what ?
- introvertmac 11y agoyes, that's the issue. They think their T-shirts worth the time and efforts we spend in finding the bugs
- hk__2 11y agoThe thing is that they never asked you to spend time finding the bugs; they’re not obligated to give you something.
- introvertmac 11y agoagreed, but "people don't know what they want, until you show it to them"- Steve Jobs
- andreyf 11y agoWell, they also put your name on their "thank you" page and sent you a nice email! What else could you possibly want? It might be a multi-million dollar business, but it's not like these hacks can actually cost them millions of dollars. Verizon has had employees giving out personal details to people on the phone for years, and they're still happy to do it even for the director of the CIA: https://www.schneier.com/blog/archives/2015/10/the_doxing_tren.html https://www.schneier.com/blog/archives/2015/10/the_doxing_tr...
- introvertmac 11y agoTrue, but people do have bills to pay. So this can't be a full time thing.
- BinaryIdiot 11y agoMildly off topic but I don't care: I'll never forget the time I was invited as an early developer for the Palm Pre. At the time Palm's website was horrendously bad security and usability wise. While waiting for their website to accept my upload I was poking around and decided to see what I could get into. I found that the addresses were something like /user/<sequential id> so I wondered "could I look at another user's page by changing the ID? Na, no way that would work"...but it did work. In fact I was able to see and theoretically control app submissions for all 500 developers at the time. This set of pages even included tax IDs. So I immediately went to Palm and told them about the issue and how to reproduce. After about two weeks they finally reported that the issue was fixed...except it wasn't. What they did was change the way the pages were accessed from a standard GET with the ID in the URL to using JavaScript to accomplish the same thing but kinda sorta hide the ID (so basically fetch content via JavaScript versus page loading via direct browsing). So naturally I was able to change the ID and still get in. It would take them another month to finally fix this issue. I was never able to convince them to let developers know their tax IDs may have been exposed along with all of their other information. I did get a special mention in one of their release notes but they spelled my name wrong :(
- introvertmac 11y agoWhat you found is called IDOR https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Direct_Object_References https://www.owasp.org/index.php/Top_10_2010-A4-Insecure_Dire...
- introvertmac 11y agoAnd yes sometime some startup deal with this very irresponsibly
- joshu 11y agoI have yelled at people for this for years. I thrilled to know it has a name. This is why the URL pages on delicious were md5'd and not the raw url_id.
- 11y ago
- enigmabomb 11y agoIt feels to me like you're getting a bad deal here. You responsibly disclose stuff and you get ... T-Shirts? I hope they fit.
- introvertmac 11y agoSometime they do, sometimes they don't :P so I make someone happy in my friends circle.