4 ms·
> First of all, please do not ignore this email, this is not a scam attempt nor am I trying to sell anything, I am just alerting and looking for help closing do
by chrisoverzero 2y ago
> First of all, please do not ignore this email, this is not a scam attempt nor am I trying to sell anything, I am just alerting and looking for help closing down a security issue […]
This seems like a good hint.
- DangitBobby 2y agoI can't tell if people are being deliberately dense as a way of punishing me for having a critical opinion, not reading the rest of the comments before responding to me, or genuinely do not understand what I am getting at. A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you. Humans famously have the capability of lying. Someone telling me they are _not_ selling something or scamming me doesn't actually tell me what they want, and it does not provide me with enough information to know that they are not, in fact, scamming me. It just lets me know they don't want me to think I am being scammed.
- ziddoap 2y ago>A hallmark of a nefarious email (particularly scams but some sales attempts) is that they aim to deceive you. The very first email has literally everything the company needs to locate and fix the issue without having to sign anything, log into anything, or pay anything. That is the opposite of a nefarious email. Nefarious "beg bounty" emails will tell you that you have an issue and then not tell you where it is -- asking for money before revealing the issue.
- quesera 2y agoFWIW, I get several of these emails per week, as the first-reader of security@ emails, and they're almost always scams, sales pitches, or poorly-disguised bounty sniffers. I can't even count the number of times I've been informed that Wordpress.com (.com, not self-hosted) has severe vulnerabilities. And those are the plausible reports. But I always respond professionally and with civility, obviously, because if they have useful information for me, I want to hear it. In defense of the researcher: Their message was better than most, and explained the issue found directly instead of couching it in BS claims. That's good. In criticism of the researcher: They should have linked to their website where they publish reports, and been more plain about their modus operandi from the outset. Let the company know exactly who they're dealing with, and what to expect. Stating it in a sentence is "good", but linking to the evidence is much more credible. I've been on both sides of this relationship. My dumbest experience was with a large bank (HQ in the Netherlands, but operating in several countries including the US and AU, and now acquired by a US bank). I reported a total account compromise vulnerability which would affect 12.5% of their users. I thought my email would be well-received and the (very simple and externally-obvious) issue quickly resolved. Instead I got threats and hostility from some SVP IS nitwit. I told him to go pound sand obviously, and it took them a week to fix the problem. My SO was a customer (which is the only reason I noticed the issue), but not for long. :)
- ziddoap 2y ago>They should have linked to their website where they publish reports, and been more plain about their intentions from the outset. I don't get this. Their intentions should be clear by the fact that they reveal the entirety of the issue (what's wrong, why it's wrong, where to find it) in the first email. They don't ask for money, hide information behind further correspondence, or anything else that would raise suspicion. The company has everything they need to locate, verify, and fix the issue without having to ever interact with the security researcher again. That's about as obviously well-intentioned as you can get.
- quesera 2y agoLike I said, it was "good", and better than most. But as the reader of lots of these emails, I'm always happier to hear from someone who is able to establish their credibility and intentions with public evidence from the beginning of the conversation. I'd like to know that I'm dealing with a professional, who takes their work seriously. And I'd like to know if I'm going to be dealing with fallout from next month's feature article as a matter of course, or if I'm being extorted to avoid publishing. (This is a thing).
- ziddoap 2y ago>establish their credibility >I'd like to know that I'm dealing with a professional, who takes their work seriously As a sender of these emails, my credibility is established when you go to the location I say there's sensitive data being leaked, and you find sensitive data being leaked. Nothing else should matter. Are you just going to keep data exposed publicly if, for example, some curious kid notified you instead of a professional? Hostility to good-faith security research, as shown in the OPs article and in some of the comments here (not specifically you), makes everyone worse off. Having myself received hostility, demands to prove my credibility, and legal threats when sending notifications like OPs, in most cases now I don't bother to notify anyone. Instead, the data just sits there, accessible to the actual bad guys. Hurray!
- 2y ago