3 ms·
The "attack" (meh) is similar to weev's AT&T hack https://en.wikipedia.org/wiki/Weev#AT&T_data_breach https://en.wikipedia.org/wiki/Weev#AT&T_data_breach but cr
by zwp 9y ago
The "attack" (meh) is similar to weev's AT&T hack https://en.wikipedia.org/wiki/Weev#AT&T_data_breach https://en.wikipedia.org/wiki/Weev#AT&T_data_breach but crucially, I think, OP can demonstrate good intent. (Or at least it doesn't seem that OP demonstrated bad intent. Weev downloaded lots of information and called journalists).
OTOH Sentinel Chain might have obligations regarding data breach (depending on where they are based) and they look Real Dumb right now. This might explain some of their aggressive response.
One of the reddit comments makes the (reasonable) point that OP (u/notarealhacker, presumably not a security pro) could have validated insecure access to just their own data from within some pristine sandbox environment. That's fair enough but when I see reports from actual security folks that IMHO go too far in this respect (the DJI bounty mess http://www.digitalmunition.com/WhyIWalkedFrom3k.pdf http://www.digitalmunition.com/WhyIWalkedFrom3k.pdf comes to mind) it seems hard to make that argument against a non-expert who appears to have acted in good faith.
It's not clear to me what jurisdiction @narh is in but here's to hoping a lawyer can mount a Good Samaritan defense if it comes to that.
- jwilk 9y agoDJI bounty thread on HN: https://news.ycombinator.com/item?id=15721268 https://news.ycombinator.com/item?id=15721268