4 ms·
> "If I wanted to, I could replace the current version of the package with something malicious, and it would start running on Google’s employees’ computers/virt
by jmole 3y ago
> "If I wanted to, I could replace the current version of the package with something malicious, and it would start running on Google’s employees’ computers/virtual desktops."
Seems like you should? It doesn't even have to be malicious, but you're much more likely to get a response (even if it's just a bug fix) by opening a window on someones computer that says "haha, you're hacked! send and email to security_team1234@google.com and let them know what happened."
caveat: not in infosec – maybe there is precedent to not do this kind of thing if you're in the business of bug bounty hunting.
- mnd999 3y agoThat would be illegal in most jurisdictions.
- frognumber 3y agoIt depends on the details. A package whose README says: "This is an automailer to send the CEO of Google a friendly Hello, and politely request changes to the Bug Bounty program." Which does exactly that, and nothing nefarious beyond that, would probably be okay. It's doing exactly what's advertised. You want to avoid anything which uses words like "hack" or "compromise." Indeed, you can go out-of-the-way to point out it is explicitly not a "hack" or "compromise" under current Google policies.
- jotaen 3y agoI’d think that ship has sailed in this case. The author already publicly stated that they would be able to make the package do “something malicious” within Google if they wanted. So however they change it after the fact, they’d run the risk of being accused of malicious intent.
- frognumber 3y agoNo, I don't believe so. "Something malicious" would be very different than sending a proof-of-concept email. "Something malicious" might be, for example, snarfing up data, or having one engineer commit malicious code and having another one approve it. Indeed, the email could walk through malicious use-cases like these, which either leak customer data or damage Google infrastructure.
- charcircuit 3y agoAnd? If someone finds a way to bypass a privacy control of a product they have broken the CFAA. If you report this bug in a bug bounty you could be charged for doing something illegal but companies choose to not to in hopes they can create an invective structure where security issues can be discovered before they are abused.
- c7DJTLrn 3y agoWay too much risk for too little reward. All it takes is a couple of the wrong people to catch wind of what happened for it to spiral into hysteria and a phone call to the authorities, and the next thing you know you're being charged for a crime by people who have no technical understanding of what actually happened. Part of the reason we have a crisis in computer security is because the good guys have to be extremely careful about the systems they poke. They can only poke companies with responsible disclosure policies in specific ways. It shouldn't be a crime to find and report vulnerabilities in good faith, but that's how it is. I almost got myself in big trouble for doing so on one occasion.
- ikiris 3y agoit's not hysteria to report people for crossing the line and blatantly breaking computer security law.
- c7DJTLrn 3y agoWhat law does it break if you publish a package that displays a popup and somebody else voluntarily downloads and executes it? There's no maliciousness, no harm done, yet somebody would find a way to get you prosecuted for it because the legislation is vague and 30 years behind. Meanwhile the actual bad guys are getting away with draining bank accounts and dumping databases with millions of peoples' personal information.
- dontupvoteme 3y ago[flagged]