5 ms·
That's crazy to not have responded to his repeated requests!
by xutopia 1y ago
That's crazy to not have responded to his repeated requests!
- benzible 1y agoAs someone managing a relatively low-profile SaaS app, I get constant reports from "security researchers" who just ran automated vulnerability scanners and are seeking bounties on minor issues. That said, it's inexcusable - they absolutely need to take these reports seriously and distinguish between scanner spam and legitimate security research like this. Update: obviously I just skimmed this, per responses below.
- bee_rider 1y agoIt sounds like they actually met with him, patched the issues, and then didn’t respond afterwards. IMO that is quite rude of them toward him, but they do seem to have taken the issue itself somewhat seriously.
- benzible 1y agoAh, sorry, I need to actually read things before I react :)
- sshine 1y agoThey already met with him and acknowledged the problem. So their lack of follow-up is an attempt to push things under the rug. Users deserve to know that their data was compromised. In some places of the world it is a crime to not report a data leak.
- nick238 1y agoPardon sir, I see you have: * Port 443 exposed to the internets. This can allow attackers to gain access to information you have. $10k fee for discovery * Your port 443 responds with "Server: AmazonS3" header. This can allow attackers to identify your hosting company. $10k fee for discovery. Please remit payment and we will offer instructions for remediation.
- moonlet 1y agoNot really if they don’t have any security or even devsecops yet… if they just have devs and those devs are people who are relatively junior / just out of school, I could unfortunately absolutely see this happening
- mytailorisrich 1y agoA company has no duty to report to you about just because you kindly notified them of a vulnerability in their software. > During our conversation, the Cerca team acknowledged the seriousness of these issues, expressed gratitude for the responsible disclosure, and assured me they would promptly address the vulnerabilities and inform affected users. Well that was the decent thing to do and they did it. Beyond that it is their internal problem and, especially they did fix the issue according to the article. Engineers can be a little too open and naive. Perhaps his first contacts was with the technical team but then managament and the legal team got hold of the issue and shut it off.
- kadoban 1y ago> > During our conversation, the Cerca team acknowledged the seriousness of these issues, expressed gratitude for the responsible disclosure, and assured me they would promptly address the vulnerabilities and inform affected users. > Well that was the decent thing to do and they did it. Beyond that it is their internal problem and, especially they did fix the issue according to the article. They didn't inform anyone, as far as I can tell. Especially users need(ed) to be informed. It's also at least good practice to let security researchers know schedule of when it's safe to inform the public, otherwise in the future disclosure will be chaotic.
- mytailorisrich 1y agoCompanies won't inform of vulnerabilities. They may/should inform users if they think their data was breached, which is different. Not clear why "the public" should be informed, either. Ultimately they thanked the researcher and fixed the issue, job done.
- pixl97 1y ago>Not clear why "the public" should be informed, either. Because it's the law in some states now. Furthermore mandated reporting requirements is how you keep companies from making stupid security decisions in the first place. Mishandling data this way should be a business ending event.