3 ms·
Yeah, huge surprise. Have you ever tried to report a technical issue to a Big Tech company, like, at all? If so, 'silence' is the best you can expect, with 'a
by antithesis-nl 2y ago
Yeah, huge surprise.
Have you ever tried to report a technical issue to a Big Tech company, like, at all? If so, 'silence' is the best you can expect, with 'a threatening letter' and 'a SWAT visit' being the runners-up.
Example of the first: if your mail server uses the default-Windows-2016-TLS stack, Facebook's mail servers will immediately disconnect after issuing a STARTTLS command and receiving your server certificate. Why? No idea, everyone else seems to be fine, but this has been ongoing for years.
Second example: you can steal any Dutch "OV bike" simply by impersonating the MiFare classic UID of any valid subscriber, without any rate limits on those attempts. I reported this issue to them in 2016, they tried to sue me and failed, then tried to talk me and failed to listen, and to this day this vulnerability exists.
Third example: phew, none (SWATs are not as eager to mobilize around here), but I would not be surprised, like, at all, if I were to get an early-morning wake-up call just for trying to correct someones SPF records via an advisory email...
- xyst 2y agoThe common issue I notice amongst companies that fail to admit fault is that they are _public_. Admitting fault means a poor market signal. Poor market signal means leadership perceived as inept and “failing to deliver shareholder value”. Of course this isn’t unique to public companies. Have seen private companies do the same for less to avoid embarrassment or perhaps they think it would harm their IPO
- antithesis-nl 2y ago> Admitting fault means a poor market signal Nah, not really. I sincerely doubt that Facebook admitting "yeah, our outgoing mail servers did TLS cert verification improperly in some cases", or the Dutch National Railways saying "yeah, we make renting bikes easy, maybe too easy" would affect their valuation. But: that does not mean that the underlying issues should not be addressed and/or that the reporter doesn't deserve a meaningful reply.
- deleted 2y ago[deleted]
- m3047 2y agoOn a quarterly scale, history shows it typically has little to no effect on e.g. stock valuations.
- toast0 2y ago> Example of the first: if your mail server uses the default-Windows-2016-TLS stack, Facebook's mail servers will immediately disconnect after issuing a STARTTLS command and receiving your server certificate. Why? No idea, everyone else seems to be fine, but this has been ongoing for years. Ok, nerd sniped. I can't likely get this fixed because I don't think I have any FB contacts for outbound mail, but I want to see a pcap and have a look at the TLS negotiation, if you provide the server hostname so I can run more starttls trials, that would also be neat. email in my profile. But yeah, good luck getting a response to big tech, I just want to know! In theory, facebook should have a postmaster that would look at email issues, but probably nobody looks at that address cause it's mostly junk.
- toast0 2y agoOh yes, I forgot to tell you, facebook.com/whitehat is pretty good at escalating issues to the right team, but I don't know if someone would triage it and say it's not a security issue and then it has no urgency.
- antithesis-nl 2y ago> but I don't know if someone would triage it Well, I have a pretty good idea, and the answer won't comfort you. To further elaborate on this pointless saga: last December, I actually met a FB engineering executive while on holiday, happened to mention this issue in casual conversation (I know: sad!) and they were going to put me in touch with All The Right People who were going to Fix This Immediately. Guess what? The "oh, if the remote rDNS ends with mail-mail.facebook.com, just don't advertise STARTTLS" 'fix' is still very much in place, and probably will be indefinitely, even if that enables the entire Internet to eavesdrop on potentially-exciting stuff like login recovery tokens. And, yeah, the saddest part is that I could actually live-troubleshoot this issue with anyone at any time, providing PCAPs, updating the outgoing mail server behavior on demand, whatever. But that's just not the way the Internet (or, I guess, anything) works anymore, I'm afraid: 25 years-or-so ago I had, like, the pager number of the person running the national backbone, and we had many late-night conversations fixing subtle-but-annoying BGP/DNS/whatever issues, which was cool. These days? Being ignored is the best you can hope for, which goes back to my original point that everything is awful. Depressing, really...
- m3047 2y agoHere's Renee Burton's (at Infoblox) comment on Philippe Caturegli's post on LinkedIn: "When we contacted DNS providers about sitting ducks attacks ONGOING in their network via lame delegation... some responded with aggression and others with ambivalence. no criminals were disrupted and it was a waste of our resources even though it was the right thing to do." And I can personally vouch that's mostly my experience and expectation as well, and not just for DNS issues.
- arianvanp 2y agoI reported a vulnerability to Amazon last year. I got initial response within 24 hours. And follow up emails every week until it was patched. Was kind of well handled. They don't do bug bounties though
- m3047 2y agoI reported weird shit happening with SYN and PING and what I got was "how dare you insult my reports" from Paul Vixie; but I used to work for him. Ultimately I blocked all SYNs and ICMP ping inbound from Amazon addresses, spoofed or not. Problem solved. Boohoo soi disant "security researchers".
- _lvbh 2y agoI have with Apple. Got a very generous bounty that paid for my university though it did take close to a year