7 ms·
Accessing Max Verstappen's passport and PII through FIA bugs
- intheitmines 1y agoJust out of interest have you had any legal threats etc from this kind of probing if they don't have explicit bug bounty programs? Also do you ever get offered bounties in on reporting where there wasn't a program?
- forgotaccount22 1y agoWhen I was still in university I reported a vulnerability and when the company started threatening me with legal action, my professor wrote a strongly worded email and they dropped it. Haven't had it since in 8 years. Feels like many companies understand what we do now, atleast compared to 10 years ago.
- SirHumphrey 1y agoThis seems depressingly common in universities. I know of a case where someone discovered anyone with a university account (so students, etc.) can edit DNS, and the IT tried to file charges until the head of CS department intervened.
- technothrasher 1y agoMany years ago when I was at school, I found a paper on a table in the computing library with a list of root passwords for some of the machines at Yale, just sitting there. I tried one and it was valid (this was the old days when remote root logins were a thing). I sent the admins a message telling them, and I was entirely ignored. A month later I tried the password again and it was still good. Luckily for me, I guess, it was before the days of suing people for trying to be helpful.
- iancarroll 1y agoActual legal threats are uncommon but I have seen some companies try to offer a bribe disguised as a retroactive bug bounty program, in exchange for not publishing. Obviously it is important to decline that.
- intheitmines 1y agoThanks, its cool to hear attitudes have changed.
- gausswho 1y agoDecline because it'd mean you were profiting off of a crime? Or that the opportunity of publishing has higher value than the bribe?
- zozbot234 1y agoThe kind of probing they did and described in the blogpost, with the attempt to raise their privileges to admin is legally fishy AIUI. Usually this kind of thing would be part of a formal, agreed-to "red teaming" or "penetration testing" exercise, precisely to avoid any kind of legal liability and establish necessary guidelines. Calling an attempted access "ethical" after the fact is not enough.
- iancarroll 1y agoGood-faith security research[0] is the only way this industry will move forward, for better or worse. It is clear that most companies do not want to invest in anything further like VDPs. [0] https://www.justice.gov/archives/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act https://www.justice.gov/archives/opa/pr/department-justice-a...
- bitexploder 1y agoWithout any sort of formally posted bug bounty program explicitly authorizing this sort of activity the CFAA prohibits unauthorized access of "protected computers". I would classify this as legally risky. If FIA had a stick up their ass they could definitely come after the researcher. The researcher's ethical standing is pretty clean in my book, but this was definitely a little more than just changing a URL parameter (only a little more). I would say this is unsafe to do if you are in the united states. The stopping point was somewhere around "I think I could provide the admin role" and reaching out to the best contact you can find and say "Hey, I am an ethical white hat security researcher and I noticed X and Y and in my experience when I see this there is a pretty reasonable chance this privilege escalation vulnerability exists. The chance it exists is high enough in my experience that you should treat it like it exists and examine your authorization code. If you would like I can validate this on my end as well if you give me permission to examine this issue. I am an ethical security researcher" ---> point over to your website and disclosed issues if you got em. To just do it is ehh... I would not take the risk. However if I /did/ do it I would definitely disclose it to them immediately and give an explanation like the above. Shooting the messenger in this case would be pretty asinine, especially if they didn't access anything sensitive, that would preclude FIA from having any evidence you did anything sketchy (cause you did not). The reason I would not do it is because you never know if a system like this pre-fetches data, etc. and that is definitely opening you up to liability of possessing PII etc. Overall, I have disclosed issues like this in the past without actually exploiting the issue to good results. Some times companies ignore it. You can always say "If you do not want to treat this issue as a vulnerability I am going to write this up on my website as an example of things you should probably not do" if you feel ethically compelled to force them to change without actually exploiting the issue. People tend to get the message and do something.
- Nextgrid 1y agoWhat he did there could indeed be legally risky. Remember that while for a lot of us this kind of security research & remediation is “fun”, “the right thing to do”, etc there are also people in our industry that are completely incompetent, don’t care about the quality of their work or whether it puts anyone at risk. They lucked their way into their position and are now moving up the ranks. To such a person, your little “security research” adventure is the difference between a great day pretending to look busy and a terrible day actually being busy explaining themselves to higher ups (and potentially regulators) and get a bunch of unplanned work to rectify the issue (while they don’t care personally whether the site is vulnerable - otherwise they wouldn’t have let such a basic vulnerability slip through - now that there is a paper trail they have to act). They absolutely have a reason and incentive to blame you and attempt legal action to distract everyone from their incompetence. The only way to be safe against such retaliation is to operate anonymously like an actual attacker. You can always reveal your identity later if you desire, but it gives you an effectively bulletproof shield for cases where you do get a hostile response.
- aleph_minus_one 1y ago> while they don’t care personally whether the site is vulnerable - otherwise they wouldn’t have let such a basic vulnerability slip through Even if they do care personally (which I would assume is often the case if the respect person is not an ignorant careerist), they often don't have the - organizational power - (office-)political backing - necessary very qualified workforce to be capable of deeply analyzing every line of code that gets deployed. :-(
- Kaibu 1y agoIn Germany, the case of a company called "Modern Solution" has gained quite a bit of traction. An IT guy found a password, tried it on the company's phpmyadmin and reported that he could access their data. They sued him and the case went up to the highest German court, which acknowledged the lower court's decision to rule with the company. The IT guy got fined. https://www.heise.de/news/Bundesverfassungsgericht-lehnt-Beschwerde-im-Fall-Modern-Solution-ab-10663649.html https://www.heise.de/news/Bundesverfassungsgericht-lehnt-Bes... (German article)
- aleph_minus_one 1y agoSome additional relevant information: When the changes that toughened the § 202 StGB were made in 2007, there were a lot of public rallies against it in which many programmers participated. These were ignored by the politicians in power. This (together with other worrying political events) even lead to a temporary upcoming of a new party (Piratenpartei) in Germany. The fact that these rallies were ignored by the politicians in power lead to the situation that from then on by many programmers the German politicians got considered to be about as trustworthy as child molesters who have relapsed several times.
- anal_reactor 1y agoLesson: instead of being the good guy and reporting shit, just sell it on black market.
- 2rsf 1y ago(playing the devil's advocate here) But that's not the case- if you find someone's physical keys in the street, will try to open the neighbor's door with it? so why is it ok to use a password that you "found" to log into a site?
- abustamam 1y agoCuriosity. I once dropped my keys on the way to my leasing office. I searched the entire complex and office for my keys. Then I saw a guy at the mailboxes trying to open each one, one by one.* I asked if he needed help and he just said he found some keys on the ground and wanted to find out who they belonged to. They were mine. And my mailbox was in the other side of the complex so all bets were off for him anyway. It costs next to nothing to try out a key in multiple places in the same proximity. Once you start going door to door using a random key you found, that's suspicious. *it occurs to me now that I write this that this behavior is suspicious as well and probably illegal. He should have turned it into the leasing office.
- luxuryballs 1y agowell at least it was a password hash :D
- dmitrygr 1y agoDon't get too excited. They never said what kind of hash. Given the rest of the site's security design, might have easily been unsalted md5
- auxiliarymoose 1y agoOr maybe rot26 — I've heard it's twice as secure as rot13!
- mulmen 1y agoIt’s 2025, you should at least be on rot52. Best practice guide: https://github.com/killerk3emstar/rot52 https://github.com/killerk3emstar/rot52
- auxiliarymoose 1y agoAh, thanks! Hard to keep up with this stuff. Next thing you know the boffins will tell us we need to switch to rot104 or even rot208 because of "post-quantum cryptography" or something.
- Group_B 1y agoThere's probably another rockyou out there waiting to happen
- GEBBL 1y agoStrange, the site is run by an Ian Carroll, but the examples show Sam Curry, who is a very famous bug bounty hunter.
- captnasia 1y agoif you look at his other posts, it looks like they collaborate often.
- gregschlom 1y agoFrom the post: "Having been able to attend these events by hoarding airline miles and schmoozing certain cybersecurity vendors, Gal Nagli, Sam Curry, and I thought it would be fun to try and hack some of the different supporting websites for the Formula 1 events."
- cathalc 1y agoThat is shamefully poor security.
- gnerd00 1y agowait until you see the party footage
- daemonologist 1y agoIt's hard to even call it security - it was just wide open... I will say though, this kind of thing does wonders for my imposter syndrome.
- whatever1 1y agoJust use a framework to build your site. Don’t reinvent the wheel!
- ChaseRensberger 1y agoi respectfully disagree with this sentiment. i think that in general, reinventing the wheel can be a great learning opportunity in understanding how the wheel works.
- AnimalMuppet 1y agoIt can. But it can be very bad at producing wheels that don't break.
- adamtaylor_13 1y agoNot if you understand how the wheel works. That's the whole point.
- jonplackett 1y agoBut maybe do that on a smaller scale personal project?
- catoc 1y agoReinventing the wheel for Formula 1 driving…
- dmoy 1y agoDepending on the wheel, maybe. Nowadays it's more standardized - same rims for example. The tires are standardized. There's a lot less freedom in reinventing the wheel in formula 1 nowadays https://www.formula1-dictionary.net/wheels.html https://www.formula1-dictionary.net/wheels.html The steering wheel of course isn't even a wheel anymore, for a long time. It's some video game console / airplane cockpit looking monstrosity.
- samarthr1 1y ago
- forgotaccount22 1y agoArchaic company has archaic security. Well done on the RD, but boy does it not surprise me one bit. Would almost be willing to bet that the hash was MD5 too.
- veqq 1y agoWhat hash do you use?
- scq 1y agobcrypt is the industry standard.
- maxbond 1y ago`bcrypt` is probably the "standard" in the sense that it has the widest adoption, but since 2015 [1] the "standard" in terms of what you should recommend for new work has been `argon2id` (and you can find parameter recommendations here [2]). [1] https://en.wikipedia.org/wiki/Password_Hashing_Competition https://en.wikipedia.org/wiki/Password_Hashing_Competition [2] https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#argon2id https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor...
- tom1337 1y agoAlso argon doesn't care about input length compared to bcrypt which only ever compares the first 72 bytes of a hash. Okta actually fell victim to this because they concatenated userid + username + password. If userid + password were over 72 bytes then the password would never be checked thus you could login with userid + username. https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/ https://trust.okta.com/security-advisories/okta-ad-ldap-dele...
- deleted 1y ago[deleted]
- megous 1y ago
- deleted 1y ago[deleted]
- LorenDB 1y agoIan, it would be great to see an RSS feed on your website if you want to gain another regular reader :)
- galnagli 1y agoIan is a great writer
- heavyset_go 1y agoSeconding this
- jacquesm 1y agoThat's not just one vulnerability, that's a whole slew of failures. For instance there is absolutely no need to keep those documents on the live server for applicants once they have been used for their intended purpose. Blast radius reduction and all that. I hope you got at least free tickets for life out of this.
- skeezyjefferson 1y ago> For instance there is absolutely no need to keep those documents on the live server for applicants once they have been used for their intended purpose. Blast radius reduction and all that. I hate this kind of post-hoc finger pointing people do after security breaches. There are other concerns in life beyond security - youre naive to think differently. Is your house secure or could somebody break past your protections? Have you harmed your defensive posture with negligence of security? Do you even care?
- zamadatix 1y agoI hope you never handle other people's PII with that attitude. It should well and beyond be treated more securely by a company collecting it than some random person's house or individual set up, there are laws about this.
- margalabargala 11mo agoThat's what you choose for yourself. How do you feel if that's also what your bank chooses for you?
- jacquesm 11mo agoI get told at least a couple of times every month that security and business continuity are a complete waste of time for your average company. So this isn't post-hoc, it is more like 'the dumb fucks don't even practice the basics and they could - and should - have known better'.
- sebasvisser 11mo agoSure, hate on the person pointing at the fire instead of the people holding the matches. If you aren’t prepared to face criticism after a failure, you shouldn’t participate in a professional environment. Without people pointing out where it went wrong you’ll never j ow what to improve upon. Because if you knew, and chose not to act..now that would be a whole new level of incompetence.
- awesome_dude 1y agoRule 1. NEVER trust user supplied data. Once that rule was broken, any other rules broken became clear to everyone
- jacquesm 1y agoYou'd think that client side security would be something that we'd gotten over by now.
- rpcope1 1y agoYou'd think but I keep meeting even "experienced" technical leadership that have been at this for a while that there's no way to get around validation and security that's implemented in client code.
- cheschire 1y agoI’ve used browser dev tools to regularly add additional drop down options to menus that weren’t present. Huel, for example, only offered 2 or 4 week subscriptions, so I added 3 weeks to it because that’s the frequency I needed, and it worked no problem. 3 weeks later my shakes arrived and every 3 weeks since.
- School-Cotton 1y agoThat’s incredible
- mulmen 1y agoDid you try adjusting price?
- achairapart 1y agoA kid in Hungary was arrested for exactly this (and it was a cheap bus ticket): https://www.bitdefender.com/en-us/blog/hotforsecurity/budapest-police-arrest-hacker-for-revealing-bug-in-e-ticket-system https://www.bitdefender.com/en-us/blog/hotforsecurity/budape...
- huflungdung 1y ago[dead]
- mvkel 1y ago[flagged]
- 9dev 1y agoThey may have said that process was related to GDPR, but that was either a lie or someone with so little understanding for basic laws that I wonder about their capability to conduct business at all. Everything about this is prohibited and discouraged under GDPR.
- necovek 1y agoAs pointed out, this is unrelated to GDPR. Many countries in Europe require you to register with the local police any visitors you are hosting and pay a visitor's tax: this is why hotels would ask for the same documents too. GDPR should help ensure they only keep the passport data until they complete the registration, and then remove it after some time or at your request.
- dboreham 1y agoAll hotels I stay at in all countries require my passport. OK, not the usa but there they want my driver's license.
- jacquesm 1y agoYou were lied to.
- paddleon 1y agomissed opportunity to grant the authors a F1 super license and get the chance to actually drive one of the cars!
- stingrae 1y agoIf only that's all it takes
- CSDude 1y agoImagine being a world class F1 driver and (someone) still have to upload your CV somewhere.
- ddalex 11mo agoa couple of weeks ago Verstappen raced in a "Advanced-amateur" competition in Germany - he had to be "trained" by an official instructor in a restricted car because he hadn't raced there before I imagine the instructor "What could I teach Verstappen now..."
- yieldcrv 1y agoresponsible disclosure made you no money and even after that blogpost you still have to take the l33tcode interview
- Briannaj 1y agomy favorite type of hacking. reading the js an modifying the PUT. Works a lot more often than you expect.
- Aeolun 1y agoThey took the website offline on the same day it was reported! That’s amazing!
- ehnto 1y agoYeah I thought that was good. The fix wasn't that long either given how fast enterprises like this usually operate.
- Jeremy1026 11mo agoI wonder how much the FIA being European affected the response. Would they have been as quick to react if they were American and knew they'd only be facing a relatively small class-action settlement?
- deleted 11mo ago[deleted]
- olliebrkr 1y agoHAX HAX HAX SUPERHAX HAX HAX (sorry)
- timpattinson 1y agodu du du du..... hax verstappen
- braza 1y agoIn 2025 I think most of the PII is just a legal liability for 99% of the cases. I once saw a custom service where you could connect your data, like Mixpanel or some analytics, and the whole motto was that this service did not want any of your PII data, and even the employees and companies that could access all the anonymous data had pseudonyms (e.g., a company named "Ocean's Eleven" with the employees Billy, Reuben, Rusty, Benedict, Linus, Basher, and so on). Does someone know any architectures or designs of applications (books or references) that take anonymity as default?
- t1234s 1y agoIs this a case where the back end has no whitelisting of what fields are allowed to be written to for that specific endpoint?
- encom 1y agoMissed opportunity to delete Lance Stroll's license.
- homakov 11mo ago>The JSON HTTP response for updating our own profile contained the "roles" parameter, something that might allow us to escalate privileges if the PUT request was vulnerable to mass assignment. We began looking through the JavaScript for any logic related to this parameter. Oh, here we go again. JavaScript brings mass assignment back. My efforts went in vein. Strong params, pls!