Stealing private keys from a secure file sharing service
timvisee.com
timvisee.com
But consider an alternative perspective: this is a company that was offering users "encrypted" file transfer mediated by clientside browser Javascript, in which there is only dubious, marginal cryptographic separation between customers and the service itself, which could just as easily serve targeted customers surreptitious DOM updates to override their claimed security capabilities.
But that fundamental problem didn't matter, because the service didn't even sanitize basic, obvious user data, and was exposed to a trivial XSS.
But then I thought, if you advertise something as "encrypted" and "secure" or more secure than competition, you should get at least basic pentest. It is not cheap to get one and a good one but that kind of XSS would be ruled out...
First to market is your bread and butter, tptacek.
The XSS-issue that was found by Tim was indeed a very fundamental problem which shouldn't have been in there. We are very happy he disclosed the information with us so we could fix it directly.
We hired a couple of professional hackers to audit our service but launched simultaneously. Biggest lesson for us: finish the audit first, launch afterwards :-)
Lessons learned here: pay your pen testers quickly because their findings can affect the reputation of your company, don't launch without responding to audit results, don't bullshit people working in high tech industries about what was happening simultaneously, don't blame tech staff for business decisions
"On the 24th of October, an article was posted on Tweakers (a Dutch tech website) showing off a newly released service to securely request files from someone through the web."
[1] https://tweakers.net/nieuws/159002/amsterdams-bedrijf-start-...
I showed the article to the company before publishing it, and it included many references and links to their website.
The contact explicitly stated he didn't like it to get published, as it might damage their product image on quick Google searches by someone researching it (even though I praised the company in the article).
Removing direct references was a nice middle ground they accepted.
Despite the lapse, they score high in authenticity, and given their small size, they deserve a second chance. Megacorps probably wouldn't have my sympathy.
(one of the creators of SafeRequest says hi!)
Hopefully we fucked up nothing else but please do let us know if we did :-) We do sanitize all input but unfortunately this one slipped through.
I'm doing a project utilizing subtle crypto and I'm, right now, doing an audit to ensure I've got that setup correctly everywhere.