6 ms·
I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told hi
by JayeLTee 2y ago
I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables.
Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims.
Again, I never asked for anything, I even offered to delay my publication so they could notify people if that was their intent, where is the blackmail here?
- DangitBobby 2y ago[flagged]
- ziddoap 2y ago>If you don't want money and it's not a scam, why are you emailing them? It may be shocking to you, but some security researchers notify companies when they are exposing data of their customers. That's it! Simple. When I notice that thousands of people's personal information is available, I also will email the company and let them know that they are exposing the information of their customers. I don't want money in return. My hobby is security, my payment is knowing that I helped thousands of people out. >I would NOT be happy to receive such an email. You would rather just continue to expose your customer's information? Interesting... I don't think you have the ethical high ground here, if that is your position.
- DangitBobby 2y ago[flagged]
- ziddoap 2y agoDoes the CEO know what?
- DangitBobby 2y agoThe motivations behind the researcher emailing them.
- ziddoap 2y agoIf my first email contains everything required for you to locate and fix your security issue, my motivations are pretty clear.
- DangitBobby 2y agoYour motivations are clear to you, the person drafting the email. If they were clear to the CEO, he likely would not have responded the way he did. Look, I understand that you reached out with the best of intentions and that my criticism is not welcome, mainly because of that. What you are doing is important. I just think if you added a bit more info to your initial email about what you want, things could have gone differently.
- JayeLTee 2y agoMotivations are stated after I explain why I'm emailing. "I'm an independent researcher who posts under the name JayeLTee. I look for publicly exposed data online on my free time and alert the companies affected to try and close the exposure." There is nothing more than that, want me to make a fairy tale story to tell the companies? I try to be as clear as possible and pass the message as clean as possible with no BS on the email, again because I'm not selling a product or a service.
- DangitBobby 2y agoYes, I did read this line in your email. Possibly the CEO didn't after his trusted rockstar team told him the issue was fixed and that they were un-hackable. Look, I think you could change up your initial email slightly to reach a higher probability of positive interactions. You are welcome to disregard my opinion.
- gs17 2y agoWhile it's hard to convey "this is 100% not a scam" without sounding suspicious, in the example of this article they tried to get it across at the very start. It's on the CEO for becoming hostile to someone who asked for nothing in return and wasn't making any threat.
- chrisoverzero 2y ago> First of all, please do not ignore this email, this is not a scam attempt nor am I trying to sell anything, I am just alerting and looking for help closing down a security issue […] This seems like a good hint.
- DangitBobby 2y agoI can't tell if people are being deliberately dense as a way of punishing me for having a critical opinion, not reading the rest of the comments before responding to me, or genuinely do not understand what I am getting at. A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you. Humans famously have the capability of lying. Someone telling me they are _not_ selling something or scamming me doesn't actually tell me what they want, and it does not provide me with enough information to know that they are not, in fact, scamming me. It just lets me know they don't want me to think I am being scammed.
- ziddoap 2y ago>A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you. The very first email has literally everything the company needs to locate and fix the issue without having to sign anything, log into anything, or pay anything. That is the opposite of a nefarious email. Nefarious "beg bounty" emails will tell you that you have an issue and then not tell you where it is -- asking for money before revealing the issue.
- quesera 2y agoFWIW, I get several of these emails per week, as the first-reader of security@ emails, and they're almost always scams, sales pitches, or poorly-disguised bounty sniffers. I can't even count the number of times I've been informed that Wordpress.com (.com, not self-hosted) has severe vulnerabilities. And those are the plausible reports. But I always respond professionally and with civility, obviously, because if they have useful information for me, I want to hear it. In defense of the researcher: Their message was better than most, and explained the issue found directly instead of couching it in BS claims. That's good. In criticism of the researcher: They should have linked to their website where they publish reports, and been more plain about their modus operandi from the outset. Let the company know exactly who they're dealing with, and what to expect. Stating it in a sentence is "good", but linking to the evidence is much more credible. I've been on both sides of this relationship. My dumbest experience was with a large bank (HQ in the Netherlands, but operating in several countries including the US and AU, and now acquired by a US bank). I reported a total account compromise vulnerability which would affect 12.5% of their users. I thought my email would be well-received and the (very simple and externally-obvious) issue quickly resolved. Instead I got threats and hostility from some SVP IS nitwit. I told him to go pound sand obviously, and it took them a week to fix the problem. My SO was a customer (which is the only reason I noticed the issue), but not for long. :)
- ForHackernews 2y agoAs I read it, he wants them to secure their systems and fulfill their legal and ethical obligations to their customers and regulators by notifying them of the breach. I'm not sure what you find ambiguous or confusing.
- polynomial 2y agoThere are 2 sides to every story, with the other side being a potential business opportunity. /s
- wang_li 2y ago> by notifying them of the breach. The breach that he actually did. They should fulfill their obligations under the law, and they should file a report with their national law enforcement agency with information about the person who is claiming to have done the crime in question.
- BoredPositron 2y agoI hope you are not in a client-facing role, as you appear to lack the ability to understand another's perspective. Security researchers rely on publications and recognition from security platforms to build their CVs. That's what he wanted. Think about it that way if everyone was a n idiot like the CEO of this ordeal we would have way less white hats.
- DangitBobby 2y agoI am in a very client facing role, and my clients quite like me. You know nothing about me, and you are completely misunderstanding this situation. I am holding the researcher accountable to how they comported themselves in this interaction instead of dick-riding a fellow hacker I actually do understand what security researchers usually want out of such an interaction. Where things fall apart is that the CEO does _not_ know, then the researcher punished them for their behavior and accessed their data, likely illegally. I am trying to communicate why they got a bad response, and why their response to the bad response was bad. I probably shouldn't have mentioned blackmail because people are focusing on that. I'm mainly trying to say "it reads like it could be blackmail" and they'd have a friendlier interaction with just a little more info upfront.
- BoredPositron 2y agoHe is absolutely in his right to write a post about it. He even tried to mediate with a third party. You are delusional if you think somebody owes you something in that situation.
- DangitBobby 2y ago> I'm simply trying to say the researcher would have more pleasant interactions with the people they email if they helped the person understand what they _do_ want out of the interaction instead of just saying they aren't being scammed. If the researcher placed themselves in the shoes of the CEO, they could understand why the CEO responded that way. That's not the same thing as thinking the CEO _should_ have responded that way. I am also not letting the researcher off the hook for responding to the CEOs response the way they did.
- deleted 2y ago[deleted]