22 ms·
After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a sc
by michael_michael 5y ago
After the Affordable Care Act went into effect I signed our company up for our state's marketplace. While browsing our plan options, I noticed the url used a scheme like marketplace.org/employers/341/plans.aspx. Of course, I tried changing the number in the url to 342 to see what happened. To my astonishment, it loaded up the next company's plans, including a list of employee names, ages, plan cost, and SSNs.
After I shopped a few other companies to see how our plans compared, I notified the marketplace operator via the only link on the website for customer service. Within about an hour, someone from their IT department rang me on the phone and started grilling me about how many other plans I browsed, and insisted that I clear my cache and browsing history, and notified me that they would be watching to make sure nobody at our IP address didn't access any other plans while the issue was being fixed.
I was pretty surprised at his response, and assumed they would be more grateful for exposing a pretty basic flaw, but I guess a natural human tendency in these situations is to try to externalize the blame. Perhaps it's more difficult to hold yourself accountable than it is to assume that others who've found your shoddy work are malicious actors.
- invisible 5y agoWhat's bonkers is that _your own data_ was also accessible. Who's to say other users didn't get that data and choose to not report and kept the data? Your own outrage to your data being exposed would have been perfectly reasonable.
- mcguire 5y agoI don't know, that sounds like a pretty valid response given that you "shopped a few other companies to see how our plans compared".
- klyrs 5y agoIf I ask you to show me a document, and you willingly show me the document, who exactly is responsible for the disclosure?
- kamkazemoose 5y agoSay you are invited to your friends apartment in an apartment building, but none of the apartments have locks. So you decide to open up some other random apartments and look through their things, who is responsible?
- the_arun 5y agoI think in this example both are equally responsible: 1. People who kept their doors unlocked 2. Person who randomly entered doors & found things. We need to take care of security of our properties, though stealing is wrong.
- klyrs 5y agoNope, opening an unlocked door is still considered break&enter. AFAIK, the "unlocked door" can even be a beaded curtain. Turns out that the legal definition of "break" in this context is extremely old and doesn't correspond to lay usage anymore. But I think that a better analogy would be asking the apartment manager to see your payment history and getting handed the entire apartment building's ledger.
- frumper 5y agothe web isn't a collection of personal apartments
- blisse 5y agoA closer analogy might be if none of the apartments had doors, would you be allowed to step inside.
- Miner49er 5y agoThat's not even close to the same analogy though. This would be like knocking on the door, asking if you can come in, and the person living there letting you in. Then getting mad about it later even though they let you in.
- 5y ago
- solveit 5y agoBeing wary of the guy, sure. But it's a terrible response in general. The correct response is to take the site down! Monitoring IP addresses? Really? First, it's trivial to just use a different IP address. Second, even if you could track people perfectly, which you can't, who the hell thinks it's okay for data to get leaked as long as you know who it gets leaked to?
- throwaway894345 5y agoIt’s not a nice response, but IT needs to be able to answer questions about the extent of a given breach (what info was accessed by whom and when). This is a legal requirement in the case of health information. Ideally people could be courteous while fulfilling their legal obligations, but IT folks aren’t generally chosen for their public relations or customer service skills.
- vageli 5y agoIn those situations you get a third-party in for forensics, you don't typically ask the people who breached how large the breach is (why would you take them at their word anyway? aren't they incentivized to downplay, etc).
- frumper 5y agoIf he can monitor ip addresses to make sure this guy isn't browsing anymore, then he should be able to check those same logs to answer his own question. If you want people that have zero obligation to help you then you should probably be nice to them. The nefarious criminal isn't going to report things like this to you.
- throwaway894345 5y agoI already agreed that this doesn’t warrant unkindness.
- marcus0x62 5y agoYes, and they need to do that based on the forensic data available to them, even if the answer is “we don’t know, it could be everything.”. Asking the person who caused the breach to explain the extent of your data loss is not an acceptable, or reliable, practice.
- vmception 5y agoits best to assume Responsible Disclosure™ is a psyop to find gullible people
- comeonseriously 5y ago> ... someone from their IT department rang me on the phone and started grilling me about how many other plans I browsed, and insisted that I clear my cache and browsing history, and notified me that they would be watching to make sure nobody at our IP address didn't access any other plans while the issue was being fixed. An IT employee who doesn't know about VPNs. Sigh.
- K5EiS 5y agoMaybe he was hoping OP didnt know about VPNs, it's not an uncommon scare tactic to imply being tracked is unavoidable.
- judge2020 5y agoI'm sure any further unauthorized access from random VPN IPs would have also been blamed on OP, unfortunately. "He found this out then an hour later random IPs exploited it. He must have initiated those VPNs".
- TedDoesntTalk 5y agoVPN doesn’t matter here. OP made it clear he was logged into the system first. Presumably all data is blocked until you are logged in. And if you are logged in, IT admin does not care about your IP address when they have your username.
- Ph0X 5y ago
- formerly_proven 5y agoI dunno, this seems pretty normal. Just today news broke that in Germany some guy who found a flaw in a web-shop backend leaking the data of hundreds of thousands of people got raided, because the operator reported him to the police - and somehow both police and state attorney found it wise to prosecute him instead of referring the case to the GDPR officer to fine the operator. It's pretty obvious that when you find a flaw you simply don't approach the people responsible for it, unless they have an EXCELLENT reputation of dealing with this. Otherwise do an anonymous full disclosure (edit: if you have an entity that routinely handles this sort of thing and has an EXCELLENT reputation, that would work too). If nothing happens, provide a PoC. Of course people, even in IT, are kind of weird here. Somehow responsible disclosure got into people's minds as The Good And Proper Thing to do, and full disclosure being somehow irresponsible. Analogy: Some guy finds out the mayor is completely corrupt or does some illegal stuff. What do you do? a) Disclose this through e.g. the press b) Approach the mayor and try to get him to fix his stuff. Somehow, when it comes to IT security, people wanna see hackers do b) because a) would clearly be irresponsible. Wtf?
- dzhiurgis 5y agoLocal CERT is sometimes happy to be a proxy, still best do anonymously tho
- thepete2 5y agoThat comparison is a bit off though, because exposing the mayor's corruption doesn't put other people and their data at risk.
- cortesoft 5y agoUmm, this seems to imply that these security vulnerabilities are intentional, which doesn't seem like what is happening. In your mayor example, you wouldn't go to the mayor because you know he is intentionally trying to break the law, so going to him doesn't make sense. Incompetence is very different than malfeasance.
- Miraste 5y agoThe problem is that the response, as it pertains to you, is going to be the same for incompetence or malfeasance in a large number of organizations. Consider what the average self-interested politician would do if you uncovered a corruption problem in their administration they did not know about. Are they going to fix the problem, reward you, and risk losing the next election beneath an avalanche of attack ads? Or are they going to bury it and crush you? Large governments and corporations are not your friends. They will hurt you if it benefits them, often very short-sightedly and regardless of the root problem. There are far too many articles like this one to think "responsible disclosure" is a safe practice. I remember one case where the red team was hired by the agency involved explicitly to perform pentesting, and when they found a vulnerability the government pressed charges!
- bawolff 5y ago> After I shopped a few other companies to see how our plans compared Yeah once you start using a vulnerability maliciously to obtain confidential data for your own personal gain, even if its a stupid vulnerability, you're not really good-guy security researcher anymore. If all you did was the bare minimum to demonstrate the vuln exists, that's cool. If after you do that you continue to use it to obtain confidential info for your own gain or curiosity, that's not so cool. > Perhaps it's more difficult to hold yourself accountable than it is to assume that others who've found your shoddy work are malicious actors. You literally just admited to being a malicious actor in the paragraph above.
- Dylan16807 5y agoBrowsing the different plans is not malicious. Jesus. And the details of different plans is not the kind of confidential info that innately deserves protection. Investigating or recording personal information would be bad, but they didn't do that.
- jjkaczor 5y agoExactly... for them to "benefit", they would have to: Apply for jobs at the other companies with better plans, proceed with interviews, offers and then finally accept one and quit their job at their current employer... To reap the rewards of their malicious hacking...
- bawolff 5y agoMore directly, they as employees could pressure their bosses to renogtiate the insurance contract.
- JshWright 5y agoIt wasn't just plan details though... They accessed names, SSNs, etc.
- Dylan16807 5y ago
- coliveira 5y agoIt is very easy for IT managers to put the blame on "hackers" intruding into the network, instead of assuming they created an insecure system. In many companies this can work.
- prox 5y agoLots of these folks (like the governor) don’t even know the basics of IT. Zero knowledge. You can tell them anything and it will stick.
- skissane 5y agoYears ago, I worked at this place, they tried to install these new core routers. The first core router worked fine, but connect the second and the whole campus network would go into meltdown. The network team could not work it out. The vendor could not work it out. But one of the IT managers had an explanation: me. Firstly, it was due to an OpenVPN I installed on a server (with permission-as a stopgap measure so we could remotely access the “next-gen data centre” because the networking team was taking too long to get the real VPN installed and it was blocking other teams on the project.) The explanation didn’t make any technical sense: the VPN is just an application, nothing to do with the core routers; but he wasn’t technical enough to understand that. They told me to shut it down, so I did (even though doing so inconvenienced the project), and lo and behold, it made zero difference to the problem. Then, he apparently even suggested at a management meeting (I wasn’t there but I heard about it) that I was sneaking in to the data centre at night or on the weekends to sabotage things, and that was why the new routers didn’t work. Apparently they even asked campus security for my physical access logs, which revealed I hadn’t been doing any such thing. Eventually, the vendor worked out the problem. When you install the router, there was a step you had to change the VRRP IDs to give every router a unique ID on the network. Clearly explained in the documentation, obviously essential, apparently our networking team didn’t read that part. You plug one new router in, everything is fine; plug the second one in, well it still has the OOTB default VRRP ID, so now two core routers on the campus network have the same VRRP ID, and all the other routers got confused, and the whole thing fell apart. Both our networking team and the vendor’s support team were so focused on chasing some obscure bug they didn’t see the basic config issue.
- websap 5y agoObviously this person from the IT department has very little understanding of how computers work, and I'm not saying they should. Each time a breach like this or in the original post happens, it makes me feel that our tools are just not there yet. If there were simple tools that caught vulnerabilities like this we would improve the standard of security.
- dataviz1000 5y agoI did that once a long, long time ago with the organization that monitors maritime piracy around the world. They have a mailing list which I accidentally stumbled on that included I assume since I only saw the one page of email addresses that ended in top level domains like un.org and navy.mil thousands of email addresses. I contacted through email the people running the organization that I accidentally stumbled on the page and they should probably hide it which they responded thank you. If you have ever been to Washington DC you would know the amount of money military contractors spend to show the latest navy vessel to everyone at the Foggy Bottom metro station and other places where such ads seem unlikely. That was the mother of all B2B email lists for militaries and shipping companies around the world. I didn't want to play any games with it. EDIT: Remembering it now, there were also email addresses with the Iranian navy as they coordinate with other navies to fight piracy too. Perhaps instead of sending a Rickroll I could have sent a mass email with Lennon's "Give Peace a Chance."
- walrus01 5y agoHuge missed opportunity for mass email of URL shortener link to the youtube Rick Astley video.
- dataviz1000 5y agoThere were cia.gov email addresses in there too. When these guys don't get a joke and fixate on you, they really fixate on you. They are more clingy than that song.
- deleted 5y ago[deleted]
- _dain_ 5y agoPeople have gone to jail for incrementing integers in URLs like that (most famously, weev).
- mcbutterbunz 5y agoDidn't he also give the data he found to Gawker before notifying AT&T of the issue? That seems like a pretty key difference here, but I don't know what weev was charged and convicted for.
- _dain_ 5y ago"Conspiracy to access a computer without authorization", which was and is completely preposterous. The Gawker part is completely immaterial, it was still a total travesty of justice. The judgement was later overturned on procedural grounds rather than on the merits (which it should have been). He did nothing that merited imprisonment, and even less so his mistreatment there.
- morelisp 5y agoIt's more accurate to say it was a travesty of law, but probably not of justice.
- tailspin2019 5y agoLooks like there is just a little bit more to that story... https://en.wikipedia.org/wiki/Weev https://en.wikipedia.org/wiki/Weev
- victorhooi 5y agoYes, but "weev" is also a well-renowned internet "troll". Basically - he appears to take joy out of denigrating, humiliating, insulting and doxxing other people. https://en.wikipedia.org/wiki/Weev https://en.wikipedia.org/wiki/Weev He's also a neo-Nazi and white supremacist. I do believe in free speech, but some of the things he does seem to take it way too far. And he famously doxed Kathy Sierra, a female technical writer who created the Head First series. I actually quite like some of the books in the series, and it's incredibly sad to hear incidents like this which actively discourage females in tech. https://en.wikipedia.org/wiki/Kathy_Sierra https://en.wikipedia.org/wiki/Kathy_Sierra I suspect there's more to the AT&T incident than just, oh, I found a flaw, let me responsible report this to the relevant parties in responsible disclosure.
- soylentnewsorg 5y agoSo his issue was not that you discovered the bug. His issue was that after discovering it, you went on to view a bunch of other people's data. What you did was walk down the block, pull on the doors of random houses, and if you found one unlocked, went in and took a look around. If you found my door unlocked and left me a note, I would be grateful. If you went in and took a look around, then did it to all of my neighbors, we would have you arrested. The bug here is an unlocked door. It being unlocked is a security risk, and people are thankful if you let them know. If after identifying the security risk you proceed to commit a crime, you're surprised people aren't "grateful?" >difficult to hold yourself accountable isn't it though... >are malicious actors so you.
- Talanes 5y agoIt's a public website. If we have to use the doors analogy, these are doors at City Hall, not people's houses.
- vadfa 5y agoAnd it's a public street. It's what inside the houses (URLs) that is not public.
- drdeca 5y agoDoors (holes-become-walls / walls-become-holes) are for controlling whether things can go through. URLs are for letting things through. A url is not a door, but an archway, or possibly a door frame.
- soylentnewsorg 5y ago..and you're not allowed to walk into someone's house if they only have a door frame instead of a locked door. they are for preventing criminals from forcefully breaking in. but you don't have to break in to commit the crime. that's why it's called "breaking and entering" - there are two criminal acts committed.
- kelnos 5y agoI don't think you're coming out of this looking too great, either. After finding the vulnerability, you then exploited it to gain an advantage, in addition to reporting it.
- cm2187 5y agoHow is it a bad response? They want to know what data has been exposed and ensure you delete that data. That's data leak 101. Why would you be defensive about it?
- yonixw 5y agoThe point being that the IT guy made sure this guy will never try to report on anything again. As they will ".. would be watching .. at our IP address .. while the issue was being fixed." Instead of a normal company having a bug bounty and sometimes even with cash prizes. Do you think google "will watch your IP" after you reported a bug? or will they give yo money? What helps in the short run? and what helps in the long run?
- munk-a 5y ago> Do you think google "will watch your IP" after you reported a bug? or will they give yo money? I honestly think they'll do both - but they won't tell you they're watching your IP because it's needlessly antagonistic.
- olyjohn 5y agoBecause you have no way of knowing if they deleted the data or not from their system. It's a pointless exercise, unless you're just gonna take their word for it.
- b112 5y agoWhen someone is kind, helpful, and goes out of their way to help you, for free!!, you have no business demanding, insisting, or threatening a single thing. Proper response would have been "Wow! Thanks!" and at worst "Please don't share what you saw, and thanks again."
- sbassi 5y ago> They want to know what data has been exposed They should check their own logs instead of relaying on a 3rd party that may not tell the truth. This shows incompetence.
- 5y ago
- watchdogtimer 5y agoI found a similar vulnerability in one of our vendors' online order system. I noticed after placing an order an integer in the order confirmation page URL. I reduced it by one and refreshed the page. Sure enough, I got all the order details of the previous customer's sale. Reducing _that_ URL by one got the next previous sale details etc. I notified the company about it. They fixed it, and in gratitude sent me a small package containing a pen and other office kitsch branded with their logo. Not much of a bug bounty, but the pen has proven useful.
- kirlfiend_grill 5y agoI let a company know that the url for their receipts (including name, address etc) was simply an md5 of the order number. They graciously offered 15% off on my next order as a thank you.
- Something1234 5y agoI feel like that would be a decent option for a surrogate key for public identification of an item and potentially cheaper than generating a uuid or something else. Maybe combine that with a salt and you have alright protection. How did you figure out that it was an md5 of the order number?
- cryptofistMonk 5y agoPresumably order numbers are easily guessable, so the md5 really offers no protection at all in this case and is no better than just using the order number
- exikyut 5y agoAnd the thing is, even if they can't be guessed, it's only 999,999 calls to try every 6-digit possibility. And you'd only take 11 days if you were nice and paced yourself to 1 req/sec.
- renonce 5y ago
- throwaway743 5y agoHaving worked for a NYC government vendor who, unfortunately, outsourced a huge chunk of dev work abroad due to low costs (and I assume the manager's shady relationships with outsourcers), the amount of bugs and blatant negligence I observed in the delivered code was staggering. Even with said mistakes the manager/project managers were more concerned with getting the project out the door, so once delievered, they'd ship usually without internal audit of the code. It makes one wonder if this is the case with the healthcare site you used, and whether or not this outsourcing of dev is common practice among government vendors? If so, it seems that we can only hope for something to fix these situations, given that government seems to only care once shit hits the fan
- justin_oaks 5y agoI can understand outsourcing development, but I suspect part of the problem with outsourcing the development is that QA of the product is done by the same vendor. "We investigated ourselves and found ourselves clear of any wrongdoing."
- YeBanKo 5y agoFor IT it’s often that whoever makes software, also tests it. When dealing with outsourcers, there comes a level of complexity. Government contractors don’t have skin in the game, and hence motivation to appropriately handle this complexity.
- munk-a 5y ago> started grilling me about how many other plans I browsed I think as soon as anything healthcare adjacent comes up most people will feel the need to get very nosey about what you accessed. It's possible they would have needed to file an incident (though, honestly, they should've regardless of what the reporter responded with) and gone through some procedure. It's unfortunate the guy was a dick about it - but asking the extent of the data you accessed probably isn't unreasonable and may have been legally mandated.
- jameshart 5y agoUnfortunately, this is the top comment and it has led to a lengthy discussion about the ethics of altering a url to retrieve a resource you should not have access to. Which is a fascinating discussion, but has nothing to do with the case at hand which is where the underlying html on a publicly accessible search result page contained SSNs of the teachers returned in the search. All the analogies about ‘it’s like asking the IRS for another document’ are all wonderfully applicable to this comment, but not remotely applicable to the actual article.
- deleted 5y ago[deleted]
- woodruffw 5y agoThis entire thread is a great microcosm of how difficult it actually is to talk precisely and intelligibly about "hacking", permissions, intended access, etc!
- michael_michael 5y agoI am now questioning the wisdom of having shared this story, and I apologize for derailing the discussion.
- jameshart 5y agoIt’s a relevant comment, and people evidently found it interesting.
- wslack 5y agoIt's a good story and relevant. Not your fault the internet got spun up in a totally other direction with it.
- nyczomg 5y agoYours is an interesting story. And very relevant. It just isn’t applicable to one interesting aspect of the article being discussed which is that the sensitive data was sent to every user but was “hidden” by html. But the shoot the messenger aspect of reporting vulnerabilities is also very relevant. It’s just the nature of forums like this that some things bubble up to the top and dominate the discussion. Hard to say it’s your fault for retelling a story.
- andrei_says_ 5y agoFear. The IT person is likely scared of (fill in the blank - blame, losing their job etc. ) They are scared because their leadership is likely also afraid - and so unable to provide protection by taking responsibility. This is the vibe of an organization where mistakes lead to blame and punishment instead of quick resolution and learning.
- rapind 5y ago“No, I didn’t look at any other plans, but I’ve notified our lawyer who is now compiling the list of exposed company plans before she contacts each of these companies for class action suit proceedings”.
- spoonjim 5y agoWhen you went to 342 you were white hat. When you went to 343 you became black hat.
- thrwwybnkvln 5y agoI found a similar kind of problem at a bank, though the vulnerability was so simple I stumbled on it by accident. I promptly switched banks but was never brave enough to report it for fear I might wind up in a very bad situation.
- bigfish24 5y agoSimilarly, a gov registration fee website simply disabled the “next” button at UI layer because I was late from the deadline. Easy bypass and paid fee, never heard anything else.
- renewiltord 5y agoOh there are so many things like this. Ages ago, I used this to find a whole listing of internal fax numbers for a government org I wanted to get someone's attention at and totally slow-spammed them using a fax API. Got a couple of reads based off that. There's no way I'm telling them I did that, haha! Rule 1: Never tell people they're making a mistake unless you trust them to trust you.
- exikyut 5y agoSerious question: how do you figure out when this is the case?
- dylan604 5y agoWithin an hour you say? That's incredibly fast. I'm impressed by that fact alone regardless of the quality of the response. I'd hae been shocked for within an hour email reply. I would have thought using incrementing IDs in a URL was as beaten of a dead horse as sanitizing your strings in a SQL query. Then again, ACA websites behaved as lowest bidder was selected.
- therockspush 5y agoGood one. A friend of mine bought a book online, that was just a link to a pdf in an S3 url. I chopped off the /book.pdf part, and it was just in an S3 bucket with all the other books they sell.
- sfoley 5y agoThere is a 0% chance this story is true.
- ManBlanket 5y agoI worked for a government contractor and I understand that behavior completely. The person you spoke with was tasked specifically with damage control. I am positive _somebody_ was grateful for your input, but those people aren't tasked with chatting on the phone. I know because I was dispatched for fixing and quantifying the scope of a similar issue, where a URL was allowing users to download treatment plans of other users. Being healthcare this is taken rather serious. While I was happy to fix the problem and grateful someone reported it, I was tasked with regularly reporting the progress of my work and scope of the breach throughout the incident. My only irk with the person who reported it was that they literally called the governor of the state after casually browsing hundreds of treatment plans, when they could've just called IT support. But yeah, I didn't talk to to them, a low-level IT lackey was given that task while I fixed the problem. Oy vey, that was a mess though. Breaches happen, everyone knows it, even companies dealing with PHI that are beholden to crazy HIPAA fines. My report ended up conflicting with a bunch of dates a former supervisor, who at that point wasn't even involved in the department, had knowingly misrepresented to the state. After the fix was merged and I documented the whole scope of the breach, I go and look at the emails and reports on the matter. She's gone told the state all about the scope of the breach, misquoted release dates of the fixes, just minimized a bunch of things with which my report directly conflicted. This person who wasn't in our department anymore shouldn't have even been involved in the first place, yet here I am looking at publishing a report that'll land her in trouble. It put me in a difficult spot. I didn't want to get her in trouble and I thought about misrepresenting my own report. In the end I figured she made her bed, my report was the definitive statement on the matter and her emails were largely reactive so maybe they'd just forget what she said. It was, and they did. The most important thing you need to do during a breach is be honest. On the other end be vocal and trust in the fact what you're doing is ultimately helpful. The government doesn't want to fine businesses. The only thing that'll end up screwing a company is if they're found to be negligent or dishonest. Negligence is easy to avoid because all you need to do is reasonably try to fix the problem once you've been made aware of it. Dishonesty on the other hand is a foot... that like a diaper-bound chubby baby, some people can't help shoving into their mouths. Don't throw IT under the bus though man, even if that guy on the phone was rude there were some good people on the matter. Some people just don't know how to act when they're caught up in a problem.