4 ms·
It's good that no harm came of it. Also, on a side note.. this is our gov, this is how they operate. I worked for a short period on a project with the state g
by SLWW 5y ago
It's good that no harm came of it.
Also, on a side note.. this is our gov, this is how they operate. I worked for a short period on a project with the state government and it was miserable. The culture is truly suffocating. I've warned many, gov jobs is where your career goes to die; there is a stigma whenever you go anywhere else even if no one says it
Miserable as in nothing ever got done, even after requesting creds (once i got certified) they dragged their feet for 3 months. It was the worst gig.
- KennyBlanken 5y agoUhhh, there was definitely harm... The FBI's helpdesk # reportedly got swamped and this probably wasted hundreds if not thousands of man-hours of agents getting panicked calls from organizations they actually work with. I'm guessing this wasted hundreds of thousands of man-hours of time at organizations around the globe as people tried to figure out WTF was going on. I'd bet a lot of people told their bosses it was obvious bullshit and were told to call a local FBI office to confirm anyway "just in case." The person who exploited this could have done a proper vulnerability disclosure. Or sent a genuinely funny/clever message along the lines of "We were lying about the aliens all along, press conference to be held at DoJ HQ this Sunday, 7:15AM" to a couple of news stations. Whoever did this came across the vulnerability and decided to be an asshole about it.
- topspin 5y ago> The person who exploited this could have done a proper vulnerability disclosure. If that proper vulnerability disclosure happens to land on the desk of some irrational apparatchik at the FBI that doesn't like your brand of facebook posts or doesn't want to be exposed as an incompetent they won't hesitate to open a file on you and dispatch a cadre of life ruining agents. And before you say "but if it's done properly..." I say hire a good Beltway lawyer before you say a mumbling word because you don't know what 'properly' is or if it even exists.
- addingnumbers 5y agoI wish they'd done a self-referential bulletin along the lines of "We have found a vulnerability in one of our security bulletin systems which allows attackers to craft and deliver notifications which seem legitimate..."