6 ms·
I’ve reported a bug like this in an application that deals with a similarly sensitive topic— They managed to call me back in 30 minutes (I never gave them my nu
by larkinrichards 7y ago
I’ve reported a bug like this in an application that deals with a similarly sensitive topic— They managed to call me back in 30 minutes (I never gave them my number) and had it fixed in a few hours.
I did contact them via every medium I could find, not just email. Obviously, the response these folks got from the company should have told them they were talking to the wrong person, and they should have been more vigilant in attempting to contact the right person.
- jammygit 7y agoHow often do the researchers get paid for doing this sort of work?
- larkinrichards 7y agoAn early stage company doesn’t have much to pay you with, but they’re thankful for the help. From my perspective, protecting the data of 10k users was just as important as— or more important than— protecting the data of 1.5m users. I feel bad when people assume negative intent. I don’t think anyone at this company wanted to violate the privacy of their users— they just didn’t get the message through the right channels.
- comboy 7y ago> protecting the data of 10k users was just as important as— or more important than— protecting the data of 1.5m users care to elaborate on a logic behind that?
- aflag 7y agoOne line of reasoning is that the everyone will know about companies leaking data of millions, so they can take steps to mitigate, whereas probably no one will know about a leak like this and just live unaware
- deleted 7y ago[deleted]
- larkinrichards 7y agoIMO, 1) early users feel the most connected with your technology and are the most hurt when you screw them over. At that stage, it can sink your company. 2) fixing this when you have 10k users prevents you from leaking the data of the next 1.49m users.
- jcims 7y agoGenerally boils down to whether or not the company has some kind of bug bounty program. If they do and it’s in scope, you will probably get paid...in this case likely $1-5k. Smaller companies that don’t have a bug bounty might provide a token reward just because, larger companies generally won’t. Any company that hasn’t explicitly authorized ‘research’ might also choose to sue.
- bredren 7y agoIn my last startup we received 5 bitcoin from Coinbase finding a relatively minor security bug. Prices were pretty low then though.
- lowdose 7y agoWith hindsight hell of a call option.
- gnopgnip 7y agoLarger companies put out bounties so that researchers will spend more time on specific issues they have.
- spydum 7y ago> They managed to call me back in 30 minutes (I never gave them my number) What does this mean? They tracked you down?
- TylerE 7y agoI imagine most mobile apps have access to the basic dialer info of the phone they're running on.
- clearing 7y agoApple actually doesn’t expose this via any iOS APIs. Not 100% sure about Android.
- omarchowdhury 7y agoPretty sure Android does. TikTok knew my phone number before I gave it to them.
- pdxww 7y agoDoes it expose any sort of "device id"? Such ids are usually asked for by advertisers and iOS and Android gladly give it to them. I'm sure there are device-id to phone-number maps out there, and anyone with money can get access to them.
- laser 7y agoUnique device IDs are app-specific.
- doktrin 7y agoAt a certain point I think we'll arrive at the collective realization that we all have digital skeletons in our closet. When we all stink, nobody stinks.
- throwaway-571 7y agoWhen everybody stink, you loose your freedom as anybody can pressure you. It’s not because everybody stink that you know they/their stink or can exploit it.
- yxhuvud 7y agoNow you are assuming there IS a right person to talk to.
- perttir 7y agoI contacted similar Finnish based application about similar issues, where almost everything, including all the user images could have been collected from the json api end point. Their response was that it is not bad system or insecure because the information is only available for logged users. So the api just needs authentication header. So all the user data could have been easily collected to own database using simple script.