5 ms·
This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify
by clobec 12y ago
This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data.
Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer.
Dealing with this via legal channels would have ensured a resolution whilst protecting customer data from any opportunistic bad actor.
Shame on you. I can't wait for myself and my wife to get doxxed now. Thanks.
Also, FYI; the whole card number isn't returned because they are probably tokenising the full card number with their payment gateway.... Or at least, I hope.
DOWNVOTING because you don't agree with me? How rude. I believe I'm a making a valid point, there are legal channels in place to help with this sort of thing.
EDIT. someone people think I do no hold moonpig responsible for this. I do! I am not blaming the security researcher. What I am saying is that some countries (like the one where moonpig is incorporated and operates) have agencies that deal with issues like these. Getting these agencies involved before public disclosure is a much nicer way to deal with these sorts of issues.
I'm aware that this exploit may already have been used but that doesn't mean that we should tell everyone about it until it is resolved. Getting the ICO involved may have resolved this issue a long time ago.
My disclosure - I have a friend that works at the ICO and she tells me that these issues usually take them (on average) 2 months to sort out. COmpanies get very anxious when the ICO contact them.
- arielm 12y agoWhile your point is valid I think you're getting doe voted because you're completely forgetting that the probability of someone malicious finding out about this vulnerability and exploring it without disclosing is quite high. Going through legal channels would just mean the api will be live for longer. Lawyers like to take their time. Instead, the disclosure resulted in the API being shut down within the hour. A much better result IMO.
- scott_karana 12y agoThe guy who found the vulnerability in 2013 could have simply reported it to authorities at the time. If their turnaround was earlier than 2015, it would have worked out better, yes?
- arielm 12y agoI'm guessing he didn't think the company wouldn't fix such a huge issue...
- scott_karana 12y agoHe could have reported this to the Information Commissioner's office in 2013, and then if either the company or the IC failed to do anything, then disclose, at this exact timeline. Then, at least, the legal system would have also been given a chance to resolve this without full disclosure and potential doxxing.
- clobec 12y agoI don't disagree with you but I still think I have a good point. He should have gone to the ICO straight away as well as report directly to moonpig then if it wasn't fixed within x amount of time, take next escalation step (which may or may not be public disclosure). Given that it's midnight in the UK now, we're lucky that they acted so quickly (assuming the offline API isn't just scheduled downtime). Going public had no guarantee that would have taken the API offline. I guess taking risks like that is easy when it's now your own data that's being compromised....
- johngd 12y agoI'll add my two cents a non-Brit: I have never heard of the ICO until this thread. Someone please correct me, but the closest thing we have in the states may be contacting the Attorney General? I say this thinking of the argument the rest of the world makes when the DMCA threat is used against a non-US entity.
- clobec 12y agoMoonpig is UK based. He could have looked up how to report a data breach in the UK. Not sure what the DMCA reference is about. I understand that people use DMCS on companies that are not US based therefore it has no power. Still not sure why you mentioned that though.
- johngd 12y agoYea, you're right; I thought that some context might be needed after I posted. They aren't related whatsoever, however the thought process of being put into the same position as the security research in this article is what made the connection for me. Assuming that the author wasn't from the UK (he probably is, but bare with me), as someone from the States I would have assumed that having an email exchange with the company was more than enough especially if there a reply on their end. From my perspective, again knowing nothing about UK law (as much as people in the UK, China, or Fiji may know about US Law), I wouldn't know where to turn after that. Maybe a teaser post, without disclosing everything? If it weren't for the fact that the author stated that he had several two-way conversations with a representative of the company, I would have more sympathy for moonpig. Speaking of which: How effective is the ICO?
- dsacco 12y agoThat's a pretty heavy handed definition of irresponsible disclosure. The onus of patching security flaws is on the company, not the security researcher. Responsible disclosure is a courteous and respectful form of helping a company fix their vulnerabilities, but it ceases to be responsible if agreeing to keep a vulnerability private enables the company to swipe it under the rug. Top security talent at Facebook and Google can patch complicated vulnerabilities in a matter of hours, days or weeks. 17 months, even for the most unsophisticated engineering team, is inane. At that point, you could have spent 17 months rewriting the entire codebase from scratch. What the discloser did here was perfectly reasonable - 90 days is typically considered the upper limit of time for a company to fix a vulnerability. This is typically the time that a vulnerability will be automatically eligible for public disclosure on, say, Hackerone. 17 months? No way. Also, downvoting is a valid way to express disagreement, see this comment by Paul Graham: https://news.ycombinator.com/item?id=117171 https://news.ycombinator.com/item?id=117171
- clobec 12y agoI still don't see why he had to do this? He has plenty of time to inform the ICO of this issue. He contacted moonpig then let the sit on this for a year. If he wants to be a disclosure hero, he could have at least told the ICO at the same time he told moonpig. The issue is 100% Moonpigs fault but he chose to disclose publicly rather than use the legal route set up to deal with these kinds of issues. The whole responsible disclosure scene needs a reboot and people need educating on the responsible way to deal with these issues. Public disclosure should be a last resort (within reason). Not even contacting the ICO before doing this is shocking to me.
- d23 12y agoYou're getting mad at the wrong person here, full stop. This is gross, inexcusable negligence and incompetence. I'm surprised this guy didn't wait more than a few months, given the severity of this problem. > whilst protecting customer data from any opportunistic bad actor Riiiight. Do you honestly think something this basic wouldn't be discovered by criminals soon, if not already?
- clobec 12y ago> You're getting mad at the wrong person here, full stop. No I'm not. I;m not angry. I realise this is the fault of Moonpig >This is gross, inexcusable negligence and incompetence. I'm surprised this guy didn't wait more than a few months, given the severity of this problem. I agree >Riiiight. Do you honestly think something this basic wouldn't be discovered by criminals soon, if not already? We don't know if anyone has already used this. We don't know if anyone ever knew about his. But now we know everyone knows about it. To be honest, I would not be surprised if someone may have already used this for nefarious purposes but at this point in time there doesn't seem to be a public dump of data for low skilled hackers to continue using for years to come. I still think this should not have been publicly disclosed in this manner. He did not contact the ICO and he left this exploit open for a year because he didn't know the mature way to handle this.
- legrandkay 12y agoYou do know that this is the first time a lot of people that do not live in the UK are hearing of the ICO
- nissehulth 12y agoI would say that the period August 2013 to January 2015 is more than "a few months".
- d23 12y agoMy wording was crappy there. I meant I'm surprised he didn't wait just a few months. As in, I'm surprised he didn't get impatient and do this earlier.
- Shad0w59 12y agoAgree with clobec, I think this is irresponsible to disclose this so publicly. There'll be a lot of collateral damage now.
- tripzilch 12y agoProbably downvoting because the whole (ir)responsible disclosure discussion has been had, for decades, with all arguments from all sides and repeating it here, again, would be just going through the motions.