9 ms·
'Impossible-to-hack' security turns out to be no security
- celticninja 2y agoOh dear, that really is a poor response by the CEO. Can't wait to see the grovelling apology he comes up with when NZ media/regulator comes asking questions
- deleted 2y ago[deleted]
- readthenotes1 2y agoThat's almost too good to be true - - that the CEO thought that Proton was the author's company
- delichon 2y agoTo be fair, security through denial, lies and intimidation is the industry standard. Leaving the passwords in clear text is double plus ungood. But my employer recently bought another outfit that does just that, and fixing it is not a near term option. So I'm stuck managing that and three of my fingers are pointing back to me.
- dieselgate 2y agoDang this is real life. “We didn’t used to do it but..”
- soco 2y agoTechnically speaking if there's nothing to break, it is unbreakable right? Also if you change the law about some crime, you don't have a crime anymore...
- cratermoon 2y agoSome powerful people subscribe to the idea that "if I (or the law) says don't touch it, it's secure". This attitude was on full display a little over three years ago in Missouri. https://missouriindependent.com/2021/10/14/missouri-governor-vows-criminal-prosecution-of-reporter-who-found-flaw-in-state-website/ https://missouriindependent.com/2021/10/14/missouri-governor...
- 201984 2y agoMissouri
- cratermoon 2y agofixed, thank you.
- coolhand2120 2y agoThat's a good one! Reporter: "Hey, you dropped your wallet" Governor: "Thief!"
- scoot 2y ago> my employer recently bought another outfit that does that does just that [leaves passwords in cleartext], and fixing it is not a near term option Could you expand on why not? I can't think of a good reason why this isn't a relatively quick fix. What's the blocker?
- ben_w 2y ago(not op, just hypothesising) > I can't think of a good reason why this isn't a quick fix. What if there's some IoT product with no update mechanism and the access password to function is stored on all of them in plain text?
- scoot 2y agoPossibly, but that's a very different scenario to a database of cleartext passwords (which is what I assumed was meant), as each device would have to be identified and compromised to access a password to a device which at that point is already compromised...
- delichon 2y agoIt requires programming in a language specific to one little known db product, in an extremely brittle and spaghettified code base . There's exactly one person in the company who kinda knows how to do it, and they're unavailable for the foreseeable future on higher priorities. We don't have the money to throw at new hires or huge porting projects. Imagine software that has been in production since the 80's, was written by a very inexperienced dev and has since been continually "organically" upgraded to handle any new promise that a nontechnical product manager feels is necessary to solve the immediate problem of an angry customer. It's a Jenga tower with a reset button.
- scoot 2y ago> they're unavailable for the foreseeable future on higher priorities Need I respond to that?
- 2y ago
- hobs 2y agoEven if a guy is an easily hackable asshole, usually accessing the stuff directly and downloading his database is still a crime (at least in the US), stay safe buddy.
- j_w 2y agoIs it hacking when there is no "breach?" If I serve a file with info I didn't intend for the world to see at example.com/secret and you access it, did you commit a crime? Clearly no. Given that, you have no way to even know if the data which was available publicly contained any private information. This guy is doing a fine public service, and any company he helps should pay him for saving their asses.
- wazzaps 2y agoYou can still get dragged to court for it[1], even if you may (eventually) win, lawyers are expensive. [1]: https://techcrunch.com/2021/10/15/f12-isnt-hacking-missouri-governor-threatens-to-prosecute-local-journalist-for-finding-exposed-state-data/ https://techcrunch.com/2021/10/15/f12-isnt-hacking-missouri-...
- j_w 2y agoBut he wasn't dragged to court for it. https://missouriindependent.com/2022/02/11/prosecutor-isnt-pressing-charges-against-reporter-who-found-flaw-in-state-website/ https://missouriindependent.com/2022/02/11/prosecutor-isnt-p...
- hobs 2y agoProsecutors are not famous for caring about internet arguments, weev (who is a piece of shit for other reasons) got sentenced to 41 months for effectively incrementing an integer in a url - https://www.justice.gov/usao-nj/pr/new-york-man-sentenced-41-months-prison-hacking-att-s-servers https://www.justice.gov/usao-nj/pr/new-york-man-sentenced-41... "he concocted the fiction that he was trying to make the Internet more secure, and that all he did was walk in through an unlocked door. The jury didn’t buy it, and neither did the Court in imposing sentence upon him today.”"
- zettie 2y agoFrom https://databreaches.net/2025/02/24/no-need-to-hack-when-its-leaking-monday-edition-teammateapp/ https://databreaches.net/2025/02/24/no-need-to-hack-when-its... DataBreaches also invited Sean Banayan to provide a statement for publication. He replied promptly to this site’s email: "We will further investigate this matter internally and do not wish to entertain this matter with your website." He really missed all the lessons in both manners, common sense and media training.
- JohnFen 2y agoOnce again, one of my rules of thumb holds true: if someone is claiming that their security is "impossible to hack", they're either massively incompetent or they're trying to sell you some BS.
- dtgm92 2y agoNot very polite or understanding. Wants to be helpful but comes across as aggressive, names and shames them, insults and ridicules them... come on, you can do better.
- JayeLTee 2y agoOP here, the one who found the exposed data. Not sure if you read my 2 emails to the company but I would say I was polite to them and was met with accusations of harassment and straight up lies. Don't expect me to pat you in the back if you come at me with such claims when I simply alerted you of a security issue.
- DangitBobby 2y agoI don't think you get to call yourself polite or well-meaning when you pan them and air their shit out publicly after they respond in a way you don't like. Maybe you were superficially polite, but you do not come across as an angel. I _still_ don't know exactly what your goals are, if you're looking for acknowledgement, payment, or just trying to make the Internet a safer place for users.
- JayeLTee 2y agoI think the around 50 public disclosures I did in the last year where I asked 0 times for anything kinda show I'm not looking for any payments. There is a huge issue regarding publicly exposed data that no one seems to want to acknowledge or talk about, what you see online? It's 100 times worse. I'm someone who is trying to raise awareness through my finds, nothing else. Also I was initially polite to the company, not once but twice, as I am to anyone who I reach out, why wouldn't I be? I want them to fix the issues, not ignore me. Don't expect the politeness to be infinite though, specially when you start accusing me of harassment and lying about the severity of the exposure that affects thousands of people, the ones I DO care about, not the companies.
- prododev 2y agoSure you do. The poster was polite, got an extremely rude response, and has no obligation to be polite afterwards. Airing their shit out is a disclosure of a vulnerability, and it's important to do. Typically you reach out to say, "how would you prefer I do this?" And work through a common understanding. The company flipped the bird, so it got aired very publicly.
- iandanforth 2y agoThe tone of the article is unprofessional to say the least. You could remove the argumentative tone, vitriol, and insults and have a more impactful article that reflected well on the author while appropriately warning people against this company. Please, don't choose team troll.
- deleted 2y ago[deleted]
- JayeLTee 2y agoNot a journalist or a reporter, posts aren't meant to be professional. The only reason I even write any of my posts is because companies DO NOT disclose incidents at all, so I have to do it for them.
- dingnuts 2y agosure you're a journalist, but the best kind! Gonzo![0] I found the tone highly entertaining; don't let the haters wear you down 0 https://en.wikipedia.org/wiki/Gonzo_journalism https://en.wikipedia.org/wiki/Gonzo_journalism
- mind-blight 2y agoI thoroughly enjoyed the post and thought your tone was appropriate, entertaining, and kind of kethartic. You didn't call them names, engage in ad hominem, or do anything click-batey. You were understandably irritated at how they talked to you and how they were clearly trying to hide a massive exposure from their users. And then you shredded them with data. A+ - And thanks for trying to keep folks like this honest!
- oskarkk 2y ago> You didn't call them names, engage in ad hominem Well, the author wrote: > Teammate App CEO, Sean Banayan, who has the reading comprehension and IT knowledge of a toddler So it wasn't very nice, but deserved imo.
- DangitBobby 2y ago[flagged]
- JayeLTee 2y agoI told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables. Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims. Again, I never asked for anything, I even offered to delay my publication so they could notify people if that was their intent, where is the blackmail here?
- DangitBobby 2y ago[flagged]
- ziddoap 2y ago>If you don't want money and it's not a scam, why are you emailing them? It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple. When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in return. My hobby is security, my payment is knowing that I helped thousands of people out. >I would NOT be happy to receive such an email. You would rather just continue to expose your customer's information? Interesting... I don't think you have the ethical high ground here, if that is your position.
- DangitBobby 2y ago[flagged]
- ziddoap 2y ago
- tptacek 2y agoI'm confused about the chronology here: 1. He discovers an unprotected database. 2. He mails the CEO of the company. 3. The database is fixed. 4. He mails the CEO again to say he's publishing. 5. The CEO replies and says there was no security breach. 6. He goes spelunking in the database tables to write a rebuttal? How does step 6 happen? What has this person exfiltrated from the database, in advance of losing access to it in step 3?
- grayhatter 2y agoStep 6 happened because the CEO in his hubris, decided it would be in his best interests to threaten someone instead of being greatful. Additionally, had the CEO responded appropriately and followed the standard methodology of all reasonable bug bounty programs, it would have included a request for the researcher to verify the fix and that there are no additional related bugs or defects with the current patch. You noticed that the email implies the security has been perfected. Did you also note that it would be unethical for a professional to blindly convey that false belief.
- tptacek 2y agoI'm wondering how it's possible that step 6 happened, not what the motivations are. It's written in multiple places as if database queries were issued after the database was taken down.
- deleted 2y ago[deleted]
- grayhatter 2y agoDid you not consider the CEO would just lie about fixing something?
- tptacek 2y agoI assume the author isn't lying when they acknowledged that it had been.
- sevg 2y agoUnfortunately, there are people out there (with a seemingly large overlap with CEOs) that have incredibly fragile egos, and any perceived criticism (such as pointing out a dreadful security failure) can result in lies, excessive reactions, defensiveness, denial, insults, scapegoating or even retaliation. Or all of the above. In situations like this, it feels to me like the reaction is “how dare you think that I would need your help?!”
- sachinaag 2y ago[dead]
- soulofmischief 2y agoName and shame. Great job, great write up.
- badmintonbaseba 2y agoIt looks like the CEO is both clueless and his reports are also probably misleading him. Whoever looked into the security problem probably saw the extent of it. This possibly got downplayed when reported back to the CEO. However rude, the CEO had little reason to lie about the extent of the problem towards the security researcher.
- shitter 2y agoI imagine the conversation between the CEO and his reports included something about "it's no biggie, the passwords were hashed using bcrypt, that's like irreversible encryption" without contextualizing that and mentioning that plaintext auth tokens were also exposed.
- badmintonbaseba 2y agoI think it was downplayed even more. Supposedly the initial email by the researcher only had evidence for leaking database sizes, and I think it's likely that the CEO only got confirmation for this evidence internally and nothing more.
- JayeLTee 2y agoAlthough I say: "This server contains over 3,8GB of data exposed including the logins for 16,500 of your users and a lot of PII and credentials, you need to secure access to the server as soon as possible." After all that transpired after etc I believe it's possible someone downplayed the severity of this to the CEO and he took that as an opportunity to ignore everything I wrote on the emails and reply that way to me assuming I was some cybersecurity vendor working for "Proton" trying to push something for the company to buy.
- wellthisisgreat 2y agoUsually like reading such posts but the author’s approach did seem very blackmail-like. The CEO is surely coming off as a crazy guy but the author isn’t a white knight or good Samaritan either. The company closed the database access and the guy says “now I will disclose it or you can do X” Would he have not disclosed it if they offered hush money? We won’t know, for his case I hope not. In any case - what was he expecting? I’d imagine there is 50%+ chance that any smaller company without a dedicated security team will take this disclosure as a threat and blackmail. Especially that on the first second and third thought it seems the disclosure would be a way for the author to boost their blog and content marketing for their consulting. If there was a bug bounty or something on their site it would have been different.
- tastroder 2y ago> Would he have not disclosed it if they offered hush money? We won’t know, for his case I hope not. In any case - what was he expecting? A bog-standard responsible disclosure that any tech CEO should either be familiar with or have someone at hand that is, as is clearly communicated in that e-mail. Both e-mails are OP reaching out to help this company out, the first fixing the vulnerability, the second giving them a chance for compliance / potential regulatory aspects they might want to follow. It's not on random people reporting security vulnerabilities to tutor random companies on this and both behaviors (non-responsiveness, then hostility) of this CEO, despite being sadly common, are actively harmful if you want to get productive security reports in the future. (And the company unilaterally signing up for bug bounty programs is rather irrelevant for independent researchers as well if they have no interest in participating in those.)
- JayeLTee 2y agoI just got offered to discuss a "token of appreciation" by another company that included deleting public posts and signing NDAs. I replied saying I don't accept bribes. If that's clear enough for you. And I didn't say "I will disclose it or you can do X". I asked follow up questions as I always do. Related to intent on notifications to regulators or clients so I can delay my report until the company does their notifications if that is their intent. I've done this multiple times for multiple companies, some I delayed the post for 3-4 months. I was actually trying to be nice to the company by not doing a disclosure before them, up until this point this was just like every other interaction I have. I sent the information, the server got closed and no one got back to me. None of my communications warranted the reply I got back from this.
- ngneer 2y agoCEO felt a threat to his company and responded accordingly. He is clearly green and impolite. Sending a vulnerability disclosure to someone without knowing their experience, and given the amount of spam on the web, one should not be surprised at the response. Trying to do a good thing and getting scolded for it feels terrible, though. One might understand why the researcher would put up database details for the world to see and fail to realize it is petty to do so. I hope both gentlemen learned their lesson.
- azinman2 2y agoI’m mostly amused and surprised to see a drag race gif on a security substack. Not surprised at any of the rest of it.
- mattdw 2y agoNew Zealander here, really thrilled to see our national medical testing service (primarily blood tests) in here. I've sent a note to them to make sure they're aware of this. Also I feel like I took the wrong path, trying to be a serious and responsible software developer - seems like all the money is in throwing shit together and making wild claims about it.
- hackburg 2y ago[dead]
- hackburg 2y ago[dead]