5 ms·
Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at gre
by cryptonector 8mo ago
Hey TFA, other people have gone to prison for finding monotonic user/account IDs and _testing_ their hunch to see if it's true. See, doing that puts you at great risk of violating the CFAA. Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution, but the moment you tested that vulnerability is the moment you may have broken the law.
Writing about it is essentially confessing. You need a lawyer, and a good one. And you need to read about these things.
- dented42 8mo agoThat feels fundamentally broken. How can you expect an organisation to respond appropriately if you don’t provide them any kind of proof?
- Faark 8mo agoHe had enough proof, his own students, who assumingly agreed. And in case the company still pretends there is no problem you could still crawl their entire user base...
- bdavbdav 8mo agoWould a better course of action here have been for him to generate a “test test” account under his?
- Alive-in-2025 8mo agothey you could kick him out of the org for "creating a bogus account" - "our company isn't bad, you're the bad actor". The bad company he was try get to fix their thing didn't behave properly, end of story. This happens over and over again because for so many companies their natural thing is to hid any problem and threaten to sue anyone who discloses. Software problems have broken that typical behavior, to some extent. I salute the author of this post who dared to do the right thing. I hope the company comes to their senses and doesn't try to punish the diving instructor. Over and over companies have tried this same "attack the problem reporter" strategy when software problems are revealed.
- krater23 8mo agoI think the right way would be to sell this shit on darknet and then anonymously reveail the bug to the public.
- phyrog 8mo agoThe blog is under a German domain, the company is from Malta. Why would they care about a US law again?
- UqWBcuFx6NV4r 8mo agoBecause Americans can never comprehend of literally anywhere on earth existing. Genuinely if any other place on earth tried this crap…the Americans would lose their minds.
- kubb 8mo agoWhy don’t you just get a rotisserie chicken from Costco and put some money into your 401k? Be careful, the IRS knows exactly how much taxes you owe.
- kyusan0 8mo agoIANAL but the law in Germany is basically the same in this case, accessing data that's meant to be protected and not intended for you is is illegal. It depends somewhat on the interpretation of what "specifically protected" ("besonders gesichert") means. https://www.gesetze-im-internet.de/stgb/__202a.html https://www.gesetze-im-internet.de/stgb/__202a.html
- master-lincoln 8mo agoCan a non specific password constitute a specific protection? I guess no
- andersa 8mo agoIt can. The fact there is a password, even if you can trivially find said password, is considered a protection. The German law is completely absurd here.
- cryptonector 8mo agoExactly. My apologies for not noticing this was over in Europe, but you'll find laws similar to CFAA all over the place. And in Europe it might be worse simply because you might have 27 different such laws _and_ the European arrest warrant, and you might not know which of those 27 laws applies. (I guess you could say the same about the U.S., with 50 instead of 27, but at least for this sort of thing in the U.S. it's mainly federal law that matters the most.)
- deleted 8mo ago[deleted]
- bgnn 8mo agoWhat is CFAA? I couldn't find anything about it in EU or Malta. Is it something in India or China? Or Japan? Hmm, maybe I'm missing another country.. Australia?
- ddtaylor 8mo agoComputer Fraud and Abuse Act
- sethaurus 8mo agoFor anyone seeking more details on this act, it is embodied as "18 U.S. Code §1030 - Fraud and related activity in connection with computers"[0], and applies specifically to the United States of America, a nation not involved in any way with this incident. [0]: https://www.law.cornell.edu/uscode/text/18/1030 https://www.law.cornell.edu/uscode/text/18/1030
- randlet 8mo agoParent is making the point that people from the US often forget that other countries exist and adhere to different rules & regulations and it seems like you're unintentionally emphasizing it for them.
- itake 8mo agoI find it interesting how American-accented people publish on social media how to access non-linked FBI files related to the Epstein leak, by updating a URL.
- ddtaylor 8mo ago> Basically, the moment you knew they were allocating account IDs monotonically and with a default password was the moment you had a vulnerability that you could report without fear of prosecution That logic is garbage and assumes there is some arbitrary point at which a user should magically know the difference between a few IDs happening to be near each other versus a system wide problem. The law would use the interpretations of "knowingly", "intent" and in this case "reasonable".
- deleted 8mo ago[deleted]
- ascendantlogic 8mo agoI forgot that US law applies everywhere.