4 ms·
Cellebrite doesn't even have a bug bounty programme or contact to report their bugs. Last year I've managed to gain partial access to one of their systems and
by tGr5lGf7 5y ago
Cellebrite doesn't even have a bug bounty programme or contact to report their bugs.
Last year I've managed to gain partial access to one of their systems and it took me weeks emailing their internal email addresses to finally fix the bug. They were total ass about it.
Now I've got complete access to their entire database and I don't know what do. Can HN advise?
- kjjjjjjjjjjjjjj 5y agoYou should not treat an unethical company ethically.
- thricegr8 5y agoPost is here and let folks take a look.
- exikyut 5y agoReally REALLY bad idea - this is one of law enforcement's larger pet gadgets and companies, so the GP would not only have a particularly enthusiastic mob coming after them, said mob's pitchforks would have automatic cannon launchers and EMPs and push-button-activated nunchucks and all kinds of other crazy things that aren't legal for standard-issue pitchforks. So if the database is fingerprintable to the GP specifically in any way, they're very very dead. And the random username doesn't even count here; they probably didn't post from Tor, so their real IP is connected to this post.
- Y_Y 5y agoI think it's a fair guess that a security researcher like that knows how to post on hn without leaving their home address. It's not particularly difficult.
- spurgu 5y agoWell this would also require him to have been properly anonymous when reporting the bugs last year.
- TechBro8615 5y agoUnfortunately HN / Cloudflare / Google still block some Tor users with the privacy invasive software known as ReCAPTCHA. Not sure if they’ve switched to hcaptcha yet.
- sneak 5y agoThis is irrelevant to the thread. ReCAPTCHA isn't a privacy invasion at all for this use case.
- deleted 5y ago[deleted]
- vorpalhex 5y agoWell definitely don't share it with DDOS secrets, news outlets or any other major company that would potentially report on it. That would be very bad press for Cellebrite, and if they connected it to you they could be very annoying - though again, they would need pretty good evidence connecting it to you and things like TOR and proper privacy practices would make that very difficult. So definitely don't do that, or use something like tails to post it to multiple SecureDrop outlets.
- sneak 5y agoThis definitely isn't a trap.