6 ms·
I am confused, they didn't contact the company at all and just disclose this publicly? Very immature handling of a vulnerability finding.
by laeri 2y ago
I am confused, they didn't contact the company at all and just disclose this publicly? Very immature handling of a vulnerability finding.
- lordgrenville 2y agoThe author says "I refuse to believe they’re unaware of this. This doesn’t feel like an oversight, it's either a deliberate design decision or they just don't care." Agree that this is an uncharitable way of looking at it.
- appendix-rock 2y agoYep. It’s just working backwards from some pre existing very negative worldview.
- aitchnyu 2y agoIts a justifiable worldview. I'm an Indian dev and I've seen obvious backdoors like these added to the backlog as a low priority bug. If somebody spends time on this, that means features are being delayed and you are rewarded less. I've worked in lambda web editor (not in Git) and my lead considered replacing sql injection with parameterised queries was a distraction/insubordination. Cant wait till audits, data breach insurance and imprisonment becomes the reality.
- AtNightWeCode 2y agoCould be as simple as no auth in debug builds and then deployed it by accident.
- JKCalhoun 2y agoI don't mean to pick on your comment, but to respond to a prior comment, you are beginning with a very positive world view and interpreting the events from there. Lazy API that did not vet a simple backdoor? Good coders but accidentally pushed the debug version of the API? I am going to have to say the second option feels less likely (yes, I have been called cynical).
- AtNightWeCode 2y agoDifferent confs in the same repo. Many CI/CD tools will pick debug/dev conf by default if nothing else is set. It was just an example. Maybe they knew.
- deleted 2y ago[deleted]
- desultir 2y agois it really a vulnerability if the entire thing is open by design?
- inquisitor26234 2y agosame thoughts, annual reports of larger companies have more dense figures than these too.
- filcuk 2y agoWho says it was? Why would they willingly give out their customers' and customers' customers data to any anonymous person or a bot? More likely a bad oversight
- imiric 2y agoFor 3 years? That would mean that no developer has ever raised these issues with management, to speak nothing of an actual pentest being conducted. No, this is not some obscure security hole they forgot about. This is plain incompetence and/or deliberate design decisions. I agree that full public disclosure like this is irresponsible, but exposing issues like this to the public is the only way for such companies to make a change or, preferably, lose business and shutdown.
- TeMPOraL 2y agoBecause they don't care, and their customers don't understand any of this shit? It feels like the usual case of vendors buying service to better exploit the users, and themselves getting burned and/or exploited by that service too.
- cwillu 2y agoThis is “the tire shop doesn't have a torque wrench” level shit. If it's an oversight, it's an oversight due to incompetency, not because a good team just happened to miss something in a crunch. Another possibility is that the issue was raised and management said to fix it later, and because software “engineering” isn't a real engineering field that holds its practitioners to any duty of care, those responsible (the engineers) just went along with it.
- globular-toast 2y agoIf you discovered an incompetent healthcare provider was prescribing antibiotics for every condition would you "contact them privately" or contact the relevant authorities? Private disclosure is for when you believe the company cares about security but made a genuine mistake. For the company in the OP it would be more like free education in fundamental privacy and ethics. They're not entitled to that. Name and shame.
- appendix-rock 2y agoSure, but what you’re describing is not what is being suggested. Responsible disclosure typically involves disclosing publicly after a reasonable period of time.
- globular-toast 2y agoRight but would you afford the same opportunity to the healthcare provider? You'd contact them privately and expect them to go and learn why over prescription of antibiotics is a bad thing and change their ways? Of course you wouldn't. You'd go to someone who cares. In healthcare there are ways you can report it without naming and shaming publicly, but how could the author do that?
- TeMPOraL 2y agoWhy? Why should they be the responsible ones, when the well-funded, well-connected service provider is acting like the fly-by-night startup (that they probably started as)? There's little public benefit in responsible disclosure here; all it would lead to is the whole thing being swept under the rug with some trivial "fix". There's lots of public benefit in immediate, wide disclosure - the scramble to fix this under pressure from vendors before potential abuse, and any real or imagined attempt at abuse, and subsequent lawsuits, would go far towards educating people and the industry about privacy, security, and bad business practice. It's a nice low real damage, high publicity case. It's not like this stuff is new. But without serious pressure, the businesses will never learn and never stop making or enrolling into such systems. Anyway, if it happened over here in the EU, I'd do the responsible disclosure thing and give a full, detailed advance expose to the local Data Protection Authority. (And if I sound adversarial, then consider that neither the vendor developing such systems, nor the venues using them, are doing it in the interest of the customers.)
- prmoustache 2y agoIs it a vulnerability when it is obvious the company do not care about security?
- shreddit 2y agoYes. Because who at the "company" does even know about this? Maybe just some coder who wrote it. But the legally liable CEO? Maybe not.
- prmoustache 2y agoThat is his job to make sure he employs people who take care of this and that the services they sell are audited by an independent organization.
- deleted 2y ago[deleted]
- friendzis 2y ago> Because who at the "company" does even know about this? Everyone who designed engineering requirements, technical requirements, test plan, everyone who wrote technical specifications, everyone who performed traceability. It was all approved by security engineers and management. > The company was founded during the pandemic when contactless dining became popular. There were tons of people intimately aware of the issue, yet for four years nobody cared.
- Brian_K_White 2y agoWho at the company gets to keep all the money?
- AndyMcConachie 2y agoDisagree. Most likely the company will blame them for trying to help. Also, if the company is so incompetent that they allow this why bother. He's not getting paid to be their test engineer.
- yuye 2y agoAnd to add that he tried out the exploit on unknowing participants. It would be better to try this with a friend in-the-know at a separate table. It makes me think he did it more as a practical joke than testing his exploit, especially because he mentioned they were "not-too-intimidating-looking guys". I'll admit it is a bit funny and the damage caused is tiny(just the price of the food). However, things like this do harm the reputation of bug-bounty hunters.
- lopis 2y agoHe could have just tried it on his own table (order on the phone, and then on the laptop through the vulnerability) and avoid having to a) bother others, b) waste food. The result would have been the same.
- 4ndrewl 2y agoThis is hardly a 0-day vuln exploit. This works as designed (and presumably design has been signed off etc)