Researcher finds flaw in a16z website that exposed some company data
kibty.town
kibty.town
Eva is an incredibly gifted hacker and a responsible one, a16z should treat them better.
We used a nodejs cms called apostrophecms that had an admin panel called global settings.
We used that for managing api keys to our auth server.
We only found out a few months in that it was outputted in the html source code. They did this so it was available to JS, of course it was in their docs. So not blaming them. We glossed over it.
Annoyingly we paid a reasonable amount of money for a pen test with one of the big consultancy companies but they also didn’t see it.
I ended up finding it and checking the logs seems like it wasn’t abused but it was shocking and a big leak
You should be blaming them. You can't excuse dangerous behaviour by documenting it. I feel like this lesson should be known by now.
If it's just some kind of generic settings with name/value pairs, then it might make sense to expose those to the browser, and make that very clear up front.
If they weren't very clear in the docs is one thing, but it doesn't appear so. Anyway, we won't combat these types of shenanigans by assuming others did everything up to snuff. We gotta be more careful ourselves.
Those are mostly used on the node side of things, but often for convenience also shared to the front end.
One problem is there is no hard definition of what is considered a "pen test". I've seen very highly reputable vendors claim essentially out of the box nessus scans as pen tests, automated burpsuite scans as pen tests.
In my own personal definition of a pen test: security practitioners may use those tools amongst others, but they generally leverage them as recon and then try to uncover pathways in from those vulns, in addition to abusing application logic and misconfiguration.
Second problem: paid pen tests have limited scope and time constraints. If the application surface is sufficiently large, that engagement may simply not be big enough to conduct a thorough test. Contrast this with Bug Bounty hunters (and attackers): they have unbounded time and resources. They can literally keep testing until they find something.. and best part, there are so many of them!
So these public bug disclosures are hard to compare to a private/paid for test. You could argue, the app owners didn't pay enough for a comprehensive test.. but the downside is: just because you paid more, doesn't mean the pen tester did a better job :( While they are high noise, I tend to think bug bounty programs are the best fit for the problem space. You end up with much deeper coverage, and a very positive ROI (even factoring in your engineers to triage the bounty reports).
Leetcode is popular hiring criteria for a reason; that kind of code checks the “KISS/don’t be clever” and DRY rediscovering known algorithms boxes
Except in a few fields, most startups are pretty vanilla config ops and secops tasks.
Recent popularity among the working class has inflated the egos of run of the mill office workers. “Programmers are lazy” has long been waved around like a badge of honor.
Rather than Silicon Valley I’d like to see a Mad Men take on IT. Start in 06-ish with a bunch of entitled first world craft beer drunkards wasting nights on syntax art, framework wars, rise of cloud. End with Covid, launch LLM AI and a bunch of code school burnouts being laid off.
A note for future researchers: the currently supported major version of Apostrophe no longer behaves in this way. Any data injection to the logged-out front-end would be a choice made at the developer level, specifically to avoid this sort of surprise.
That said, there are still use cases for including API keys as part of the configuration and 'content' of certain types of widgets.
For context, I am the head of design at Apostrophe and also play an engineering role.
Overall it's a great & in current headless craze a unique product. V3 looks very good, but we never got that in production.
How was such vuln not found and abused in this case? a16z is very lucky or maybe it was abused and not disclosed. Researcher or bored person with a kind heart/white hat hacker mindset is the first to reach out.
a16z should be fined heavily unfortunately there is no legal framework for this type of negligence
Maybe it was..
There might have been more value in leaving this one open than just screwing with them.
That's a clever lifehack to save your company money, by not having any way to privately contact engineering all bug bounties will have to be reported publicly which means you don't need to pay anything.
(Note: I still think A16Z should have paid them.)
A single email bouncing is frustrating of course, but he then posted that an easily found vulnerability existed on Twitter, while a16z:
- has a contact page page https://a16z.com/connect/ with 4x emails to their offices at the bottom (despite claims the main site had no other emails)
- links to their Twitter where DMs are open https://x.com/a16z same with instagram, FB, and linkedin, all open
it would be easy to just email all of them at once and waiting a couple days to see if it gets escalated.
Someone shouldn’t have to jump through hoops to help the company secure its resources. That is not how this works.
A lot of pentesters are just kids who are angry at the world and the poor state of security, which I get, but it's not a huge barrier to try a bit more. He would have been rewarded if he did.
It is by far in the company’s best interests for this to happen because the alternative is public disclosure or disclosure to black hats instead.
Anything more is jumping through hoops. It should not be the researcher’s responsibility or burden to go out of their way to help a company that hasn’t done the bare minimum to welcome white hats helping them secure their own systems.
Any dev knows what it's like having a million responsibilities, a lot of things get put on TODO lists that never get completed. Them being owned by a wealthy company doesnt mean they have a huge dev team running 247 to handle this stuff. Which is probably why such a obvious failure even happened...
Security researchers get high and mighty extremely quickly, which is immature IMO.
>Any dev knows what it's like having a million responsibilities,
Any airplane mechanic has a million responsibilities, and if they are not followed people fucking die. Maybe software devs should step up and take a little responsibility for their lack of action that can have consequences for their users.
Security researchers owe you nothing. If you make the path of least resistance selling sploits to blackhat groups the world will be a worse place.
> Security researchers get high and mighty extremely quickly, which is immature IMO.
Immature would have been not trying to responsibly disclose this, or disclosing the hole before it was patched.
Click nav
click “how to connect with us” -> https://a16z.com/connect/
See 4 emails at the bottom for each office
See 4 links to social media pages where every single one has DMs open
Wait at least a couple business days to see if anyone replies, if no one does or it’s not being taken seriously then you can announce it publicly on social media you found something but can’t reach them
Okay. There’s 4 front office emails and 4 social media accounts, both presumably manned by non-technical folks.
So now you have to go back and forth just to get routed to the right place. Which may not even happen if this is the first time that employee handled a security incident.
You’re making it sound like sending the email or DM is the end of the work. That is usually far from the case.
If they're putting the effort into vuln scanning the site, they can also put in the effort to get in touch like a professional. You could just as easily say "why should the onus be on the researcher to find vulnerabilities when it's A16Z's job to secure their own site". The researcher is in this to find holes and make a few bucks (which is fine!). The job is complete when you get in touch.
Presumably, the company wants to be as secure as possible. It’s in their best interest to make this process as painless as possible. A security researcher has many options for what to do with a found exploit, some far less moral than others. The company has very few, relatively. They are the ones that are limited and therefore should be doing everything in their power to ensure the best outcome, a responsible disclosure that is fixed as quickly as possible.
The best way to ensure they do this is to provide an obvious, easy to find avenue for these things. This includes reasonable, well-displayed emails (or using something like a standard abuse@, etc) and a bug bounty.
Simply put, the company is the one that should be going out of their way or else they will just have researchers either disclosing it publicly or selling the exploit for likely far more money than a bug bounty.
But many don't. And a lot of things in the business world are not as they should be. And in this real world of imperfection, others sometimes need to put in effort (and be paid for that effort) to make up for the failings of companies. This is one of those cases of imperfection.
That doesn’t change anything. Just because a company has shitty security reporting practices doesn’t suddenly mean the onus is on the researcher to do the company’s job.
They did. They emailed, and when that was bounced, they used a different medium to reach out. Twitter is a place that many companies actively engage with the public.
> The job is complete when you get in touch.
They got in touch. If A16Z aren't going to respond to people via email, but they do on twitter, they don't get to decide that twitter isn't a viable communication platform.
This is especially egregious given that A16Z’s DMs are open.
>Money is something VCs “print” and manipulate.
You wot m8
They also have contact email addresses listed at the bottom of https://a16z.com/connect, which the researcher conveniently missed.
They were looking for clout, not responsible disclosure.
It's polite to say thanks if someone informs you that you accidentally left your backpack open.
But in no way you are supposed to give them anything.
Even further, some people take precious things from your backpack (trying to exploit the issue) and then come back to you asking for money; claiming they are nice people. This is non-sense.
I would have thought that was completely obvious so maybe that's not what you were asking?
(On the other hand this is HN...)
Being anti-VC is essential being against technological and economic progress.
Not everything that happens is progress, the world can often do without 'disruption'
The value of the wallet is not the cash you'd directly lose inside of it. The value is getting your ID and cards back without them being copied by someone else, along with any other identifying information.
The value of having and up front and easy to use bug bounty system is it's easier to use then selling it off to some blackhats (hopefully). Those blackhats may otherwise scrape all your s3 buckets or somehow otherwise run up a zillion dollars of charges over a holiday with your keys.
Being cheap gets expensive.
Acktchually, depending on where you live, you might be.
It’s in everyone’s, especially the company’s, best interests to have a bug bounty and easily accessible security hotline. Expecting researchers to jump through hoops like contacting their offices’ front desks to get to security is absurd.
That is pretty much what they did. Posting publicly about the vulnerability most certainly meant that every hacker in the world tried (and probably succeeded) at reproducing it, all before the company had enough time to act.
Because this is explicitly what happens when a company doesn’t have a good process for accepting and responding to exploits.
The onus should entirely be on the company to invite researchers to find and report exploits in a responsible way. They are the ones at risk of losing millions of dollars over an exploit.
It's a16z, not Grandpappy's Model Railroad Museum Showcase ("Come see a photo of the tiniest steam wagon in Sheboygan!").
> someone from @a16z get in touch, now. its bad. security related.
https://x.com/xyz3va/status/1807330215955177937
If your email bounces, I think reaching out over social media is reasonable for a fast response.
All channels were ignored, so I have to resort to contacting our government agencies. Luckily, one agency replied to me and had one of the devs contacted me. For this hassle I was only paid $50.
You have no idea the effort we go to report this things. So I quit bug hunting after that.
I mean, a16z should be very grateful this got reported by an honest hunter regardless of the means it was reported.
If there is a next time, maybe I'll try convincing the cybersecurity bureau to take my vulnerability reports instead.
They seem to only want you to connect via social media (which is a poor choice for primary contact IMO).
i had no ill intentions. stop pretending i did.
They have those now. Do we know they did when the researcher tried to reach out?
Edit: I decided to take a look at it myself. It does seem that that was available on June 3rd of this year [0]. (You'll have to look at the source since the archive doesn't do their animations.) It seems to be available on previous snapshots as well [1].
[0]: https://web.archive.org/web/20240603210532/https://a16z.com/... [1]: https://web.archive.org/web/20240000000000*/https://a16z.com...
[0]: https://web.archive.org/web/20240603210532/https://a16z.com/...
The researcher found an email address, tried it, it bounced, then reached out over Twitter with:
> someone from @a16z get in touch, now. its bad. security related.
https://x.com/xyz3va/status/1807330215955177937
That doesn't seem irresponsible to me. Sure they could have searched the bottom of a connect page for the office emails to try, but I don't see any significant issue with what they did instead.
It’s obviously not safe to publicly announce the existence of a security vulnerability, and there was no barrier to alerting them privately via the same platform.
Publicly showing the vulnerability would have been unsafe, but I don't think there's much harm in asking to get in touch about an unspecified security issue (not even saying that it's a vulnerability in their website). Andreessen Horowitz is a massive firm, not some tiny website flying under the radar.
> and there was no barrier to alerting them privately via the same platform
DM would have to get picked up by their social media person next time they check Twitter, whereas a directed tweet can additionally leverage networks and be escalated by people with contacts - possibly someone could give the up-to-date engineering contact email, for instance.
Either way would have been fine, really. I feel we're going over the actions of an individual researcher with a fine-comb, searching for any hint that there was an arguably better course of action, when there are multiple huge obvious mistakes from a16z.
You're going over things "with a fine-comb". I just wrote two sentences that made a single point.
Should the hacker have tried more? Sure, maybe. Do I really care? Definitely not
There might be a legal distinction between "breaking and entering", "burglary", "trespassing" etc, and in a legal sense, whether the front door was open might have some impact on whether the act was illegal or not and what the consequences are, but in colloquial usage, you've still been robbed.
I think this is a more apt analogy to what az16 did here
But IMHO it’s hard to feel to bad for someone (az16 in this case) who handles their arguably most valuable goods in such a manner and gets robbed.
It's not an invitation to take it, it's just really stupid.
The particular problem here is we think of the crime on the web in a civil/criminal manner... "People should just follow the law or be punished for a crime". This is not the internet. Regardless of what you think about the internet, it is an international war zone. If you leave the hatch of a tank open and a drone blows it up, that was you being stupid. If you leave an ammunition truck unguarded and the enemy takes it, again, that is you being stupid.
History will look back and say WWIII started on the web, but as of now it seems a huge number of people are in denial about it.
Do you cultivate vines with fruit, or do you cultivate brambles and eat thorns?
Remember white hats don't need to exist. Black hats will exist by the very nature they are parasitic and thrive where exploits exist. We can either have a community that warns you that "Hey, the stuff on your porch is going to get stolen" or we can have a community that calls their buddy when they see some stuff fresh for the taking.
A huge portion these discussions under this article are people arguing the minutia of a puddle in the lawn while a 10 meter high tsunami is rushing their way.
If there were a convention of leaving stuff on your porch to donate it, and a general assumption that when people left stuff on their porch it was up for grabs, somebody started storing their groceries there, and they were taken… they would just be stupid and not sympathetic.
If somebody just moved to a neighborhood where this was tradition and didn’t know about it, they would rightly be a little bit annoyed when the groceries they stored on their porch were taken, but really they only have themselves to blame for not understanding the local conventions.
If somebody opens up a storage company and then just put all the customers’ stuff on one of these porches, they are just dangerously, unethically incompetent. Even if there isn’t a convention of taking stuff from porches, actually. Because there are also armed gangs (nation-states) that go check out people’s porches for secrets.
Only the burglary, trespassing, or B&E parts. Theft is still theft even if you leave your doors unlocked and/or open.
If someone doesn't know they've been a victim of larceny until later, it wasn't a robbery.
In this case, a person was yelling through the front door "Your door is wide open!" and no-one was listening.
For a 42B AUM company, at a time where running an IT operation means "use CrowdStrike so that you pass audits", leaving the front door open all night should get you fired, regardless of whether you blame hackers or not.
If I wanted to try to use such a weak analogy, the analogy to hacked is not robbed. You were only robbed if content was removed and exclusively held by someone else, which in the security world we call a ransom.
You can see how quickly this breaks down.
while the world burns with botched software updates.
botched software updates on a Friday is just the chef’s kiss
No surprise there.
Using these keys to access unauthorized systems is a crime.
This is a major difference.
Thank goodness the internet isn't an international operation filled with nation state level actors and questionable companies running data gathering operations from places they cannot be touched.
Always assume your data has been stolen by an assailant in a place that's only reachable by launching nukes at them. Also assume there is some competitor on the other side of the world now using your data against you.
Please stop treating data theft like Barney Fife level candy store theft. A huge portion of the time even if you know the name of the exact person who did it, there isn't going to be shit you can do about it.
Turns out, not much.
I do know that "Bidenomics", aka the torrent of federal money (CHIPS Act, Inflation Reduction Act, EPAs new "Green Bank", Dept of Defense's retooling, etc), has been a huge boon for startups.
I would have thought a group of savvy entrepreneurs like a18z would join the renewable energy and domestic manufacturing bonanza.
But like I said, I don't understand finance. So I'm sure a17z have their reasons to sit this one out.
Maybe marca and ben meant Trump would be better for VCs and tech investors. Which would be true.
That's certainly one way to offer a response!
It's obviously not foolproof, but it's a good effort.
A little tired because you didn't sleep well, or worried about a relative in the hospital, or you stubbed your toe that morning and it's distracting... and whoops.
No really this is unacceptable for a professional, it’s even bad for an amateur.
If your processes are so insecure that a little tired breaks your whole company you done goofed.
Also bizarre to frame this as “unacceptable behavior”, as if whoever is involved was in some way aware of their mistake and/or would say “this is acceptable behavior!” when confronted with it or something.
This is unacceptable behaviour for a professional in my eyes.
The person I replied to understood it as “piling on more and more agile bs” but IMO that was just bad faith so I ignored it.
You need both - processes that are lightweight but solid where it matters - operators who give a shit
But if they have five security processes that each has a 99% chance of catching a bug, that's still a 1-in-10,000 chance that something will slip through. And I'd wager that a16z has more than 10,000 "components" that goes through those processes.
By not building this yourself and instead outsourcing the work to India, to people that work for 4.00$/h
And I'm not blaming the person that has to work for this little cash for delivering shoddy work like this.
additionally, i didn't realize there are tools to automatically discover unreferenced subdomains like this. i would have just assumed security by obscurity
I've put internal sites behind AWS ALB's plugged into an OIDC provider[1] (Google), which works well.
1: https://docs.aws.amazon.com/elasticloadbalancing/latest/appl...
I just don't understand this petty attitude. This almost guarantees next time somebody that finds vulnerability with a16z or any of its companies to seek black market rewards that will do far more damage.
This is just like when KakaoTalk refused to payout bug bounty because you had to be a Korean citizen which ended up causing more vulnerabilities to be discovered in the wild.
Companies and billionaires reading this, please don't be petty like Andreesen. Guy went from a leader to a borderline security fraud artist. You don't want to be earning more ire from the public in the current political climate. It's dangerous.
> “On June 30th, a16z addressed a misconfiguration in a web app that is used for the specific use case of updating publicly available information on our website such as company logos and social media profiles. The issue was resolved quickly and no sensitive data was compromised,”
What the fuck is this? They are blatantly lying here. There was a lot of sensitive data compromised. Anyone who inspected the site could have had access to everyones emails.
> the compromised list of services:
> their database (containing PII)
> their AWS
> their salesforce (never checked, account may be limited)
> mailgun (arbitrary emails from a16z domains, and also could read older emails)
> ... and probably more
https://en.wikipedia.org/wiki/Neko_%28software%29
The Wikipedia article is missing the implementation in the article. Too bad they don't pay bounties.
^ ^
0 -
*
-What is best practice here? Do you first tell the company that they have a security issue, ask for bounty and then help? Is that unethical? Blackmail?
Means what exactly? What information did your public reach-out include?
EDIT:
Ah, I think it's a tweet that said:
> someone from @a16z get in touch, now. its bad. security related.
Lol, ok. I guess they don't want anyone to know they had a security vuln. I wonder if they make you sign an NDA too when you get the bounty.
1. "Surprise pentests" are illegal in the US and pretty much every jurisdiction in the world. If you are actively breaking into websites without a prior agreement, you are not doing anyone a favor. Save your efforts for companies that actually want you.
2. If the company doesn't have a published bug bounty program, they don't owe you anything. Yes they can still be nice and pay you, but they definitely won't if you disclose the vulnerability to the rest of the world without giving them a heads up and enough time to fix it.
3. "Oh I couldn't find an email address" is the worst excuse in the world. I found one after exactly 5 seconds of Googling (at the bottom of https://a16z.com/connect). And even otherwise there's Twitter, Instagram, LinkedIn and a hundred other ways to reach someone at the company if you really want to.
This is classic case of clout chasing over responsible disclosure.
They viewed the source code. Despite what the governor of Missouri[1] thinks, that's not hacking.
[1]: https://www.theverge.com/2021/12/31/22861188/missouri-govern...
No.
"i like to do this thing where i search twitter, looking for companies, and then try giving them a quick pentest"
"the compromised list of services: their database (containing PII), their AWS, their salesforce (never checked, account may be limited), mailgun (arbitrary emails from a16z domains, and also could read older emails) ... and probably more"
By their own admission, this is a "pentest", and they were able to access a16z's "database" and ascertain that it contains PII. Amongst other services used by a16z.
I'm not the one to judge whether they crossed any legal (or moral) lines though.
>a16z did not give me any bug bounty on this because of the fact i publicly reached out instead of trying to reach out privately. the only reason i did it this way was because:
> there was no available contact on their main site
> the email i could find engineering@a16z.com bounced my emails
The age-old practice of screwing over security researchers over any possible technicality is still alive and well. Brings tears to my eyes.The sad thing here is what has to happen is the data needs sold off to blackhats to the point that entire countries get pissed and start putting near draconian level regulations and fines against companies like this to get them to stop this insecure bullshit.
Finding random email addresses and sending them a notice would have gone no where other than spam folders. I get dozens of "disclosures" every week from mostly script kiddies that think my DKIM setting is somehow going to be the end of my business. My brain automatically ignores emails like it.
1. Caused by pure ignorance and completely avoidable (this bug).
2. Caused by subtle configurations, workflows, programming (mostly avoidable, secret scanning, security linters, code reviews, general intelligence, etc). This is where 99% of security bugs are.
3. Caused by a malicious actor aligning planets with a single intent to maximize their cause. You'll never stop these people (three letter agencies, state actors).
edit:
A must watch talk https://vimeo.com/95066828
See crypto, Clubhouse, "it's time to build [not in my Atherton neighborhood]", e/acc Nick Land manifesto, Trump '24 support, etc.
||www.kibty.town/files/js/oneko.js^$importantSurely any contact would have sufficed to at least try to get an introduction to their security team?
If you browse their website there are loads of email addresses for various offices and divisions.