The Firing Offense
thedailywtf.com
thedailywtf.com
It was a big enough WTF that there was no nonce or time element to the authentication, so that if you got hold of a cookie you could replay it forever.
It was a bigger WTF that the "encryption" looked suspicious, and turned out to simply be base64 of the customer ID.
In a tripple whammy, the customer id that was "encrypted" was a sequentially assigned integer, so it took me about 10 minutes to demonstrate that I could access the accounts of everyone in the company and every customer simply by working backwards from my own id.
Thankfully my boss at the time was smart enough to not playing shoot the messenger. They thanked me, and were somehow amazed that I'd figured out how to "break" the encryption, and asked me to review their fixes, and we went back and forth a few times until it was reasonably secure.
http://w2.eff.org/legal/cases/Intel_v_Schwartz/schwartz_case...
The thing started to refuse to launch after a update on Windows, and this started a long talk with their helpdesk and people in forums. Eventually I was convinced the bug was in their DRM, found a cracked.version, and indeed the cracked version worked just fine.
I told this finding to the helpdesk, hoping they would fix it, or at least say sorry...
Their reaction was call me a filthy pirate, delete all my support tickets, and after I wrote.the whole tale on.the forums they quickly hellbanned me, by removing all permissions.instead of.banning me, so other users.think.I left, not that I was banned.
Mobile HN has been a problem since we started accessing the site with our phones, but has never been addressed.
[1] https://play.google.com/store/apps/details?id=com.touchtype....
I used to play an online soccer manager game. One day I found out - essentially because I had copy/pasted a bit of buggy javascript into their homebrewed forum to help them spot the bug - that the forum itself would execute any javascript a user put into their posts.
Alarmed, I notified everyone I could think of. And waited. Knowing these guys were infamously non-responsive, and that this was a pretty bad issue, I then posted about it for everyone to read to raise an uproar and get their attention. Which it did. And we all waited.
Finally, I posted a small script that popped up an alert with "You've just been infected by a nasty bug", put it in a few places with "tasty" subject lines to get people to click & read it.
Oh, they fixed the bug. I also received from the non-technical Forum Moderators - real quotes, I kid you not:
-- one week forum ban for "taking advantage of a bug" because "someone had to be punished for this"
-- one week forum ban for "spamming the forum" (I had post I had a great player for sale to get clicks, then explained the security flaw instead in the post)
Users were outraged at the bug; moderators of the forum were outraged that I had caused such a PIA by causing all these popups when they were trying to browse the (insecure) forum
Obviously you thought it was urgent and maybe the admins weren't being responsive enough. You have to keep in mind that priorities vary. Always keep in mind, there are real people on the other end who have to deal with this. What if your actions dragged an unhappy parent away from a sick child to deal with a PITA who thought his issue was so important as to demand immediate attention?
It's how security disclosures work if the vendor is not cooperative enough to fix the broken stuff. It's better to get the bug fixed silently, but if you can't get that, then for users it's better to have the problem known widely to public and thus fixed on short notice than for it not to be fixed for a long time, risking exploiting by malicious individuals.
> What if your actions dragged an unhappy parent away from a sick child to deal with a PITA who thought his issue was so important as to demand immediate attention?
It's not OP's problem. One can't take responsiblity for everything people will do because of a comment one wrote. Otherwise you'd have to bill me for the time you spent reading this comment instead of working.
And by "no response", I meant "no response", not "no fix".
Each of those periods was a 24-hr wait.
I appreciate your sentiment, but in this case I knew precisely who I was dealing with, and their reputation for (not) dealing with things.
She replied calling him a creep, and reported him to the dating site.
I'd figured out that the barcodes used on our school lunch cards were just plaintext for our ID numbers. With minor cooperation from a nice lunchlady, I discovered that there were a couple very low numbers (e.g. 00000001) that had effectively infinite funds. Presumably they had been used for testing or something.
I brought this to the attention of the schools tech guy, who thought it was very cool and said he'd go tell the administration so he could get permission to fix the issue.
Of course, being a middle schooler with access to a card printer, I also took this opportunity to reprint my lunch card with an identical design and barcode... And a Chuck Norris photo.
The administration asked to speak to me and I assumed I'd be thanked for finding an easy vulnerability that could have been losing them funds.
Instead I was told I would be expelled or at the very least suspended for a month, and that they thought this constituted a felony and identity theft. Ridiculousness of those claims aside... I ended up getting a away with weekend detention after my parents and the tech guy stood up for me.
They simply overreact and lash out.
I built myself an arduino mag spoofer: http://lifehacker.com/5677465/diy-arduino-magstripe-emulator And figured out how to iterate through the issue numbers. Got into someone's apartment with their permission, then went to the IT people.
The lead IT guy was cool (we had a friendship from my first day there), asked me to read his card and we went and opened the server room. He escalated it up the chain. Not sure if it was ever replaced with something more secure (doubtful).
The best approach may be if you are unsure as to what the response will be when you feel like you need to disclose a security vulnerability is to do so anonymously.
One day there was a power cut which meant that all the card readers stopped working and we couldn't open the server room doors. After ten minutes of scratching our heads and worrying about the UPS batteries running out, someone had the bright idea of dragging a desk next to the door, moving a couple of ceiling tiles and climbing over the partition wall.
The guy didn't get fired but I'm not sure if that particular vulnerability was ever fixed.
If ever you find yourself discovering a security flaw then just pretend you never discovered it and tell no one. If you really want to be a concerned citizen - report it anonymously.
So stay quiet and let the real bad guys figure it out.
There are also many who make reasonable incomes selling exploits on the black market.
I got a magstripe reader for a project and had some fun swiping various cards and seeing what was contained. My drivers license had the number and my address which was interesting. The only cards I came across that weren't obvious plain text were hotel keys.
Even their ATMs are defective by design, they spit out the cash before the card so a LOT of people leave their cards behind at the ATM, when this issue was solved like 20 years ago in the UK by spitting out the card first and beeping until you took it.
The main things you have to look out for are coercivity and tracks. Magnetic stripe cards come in both high-coercivity and low-coercivity (HiCo and LoCo). This is a bigger issue if you're doing writing, I believe most readers are compatible with both. There are typically 3 tracks of data available, so you'll also want a reader (or writer!) that can access all three.
The model I got could be programmed through a Windows only utility and that seemed pretty standard, so at least make sure you have a virtual machine with Windows on it. You'll need to program it to tell how to interact (as a keyboard is easiest) and if you want to fiddle with the tracks.
http://web.archive.org/web/20061205043511/http://nique.net/i...
http://en.wikipedia.org/wiki/Billy_Hoffman
I met him while at Georgia Tech; he's an incredibly bright person.
But yeah, Do... Not... Report... security issues unless-
1) The company has a history of being "chill" with that kinda thing: e.g., Facebook, Mozilla, Google, etc.
2) You do it super-anonymously. Like, drive 3+ hrs away to a college campus you've never been at. Go into their computer lab when it's really busy. Create a new yahoo email account with a name that is opposite from any hobbies you have, through a proxy in another country. Send them an email not using your regular grammar style. Stay in the lab for 3 hours, send the email during the 2nd hour. That way, if there are any cameras in the room they won't just see one person walk in and walk out within the 5mins the email was sent. Then leave the lab and never return, never log into that email account again.... ever.
Is this why most layoffs start with middle management?
The less work you do, the more you'll keep everyone happy, and the higher your job security. If you try actually getting anything done, you will make people mad and lower your job security.
I suspect this is true in many/most large organizations, not just universities, yeah?
A straw man is typically used to indicate that you think someone has misrepresented your position, and then attacked the misrepresentation rather than the real position you hold.
For example:
A: The world looks flat because you cannot see over the horizon.
B: THE WORLD IS NOT FLAT! THIS HAS BEEN PROVEN TIME AND TIME AGAIN! I mean if the world was flat how would satellites work? Idiot.
A: I never said the world is flat. I said the world LOOKS flat.
B: Are you an idiot? The world is NOT flat. This has been proven time and time again, you can literally sail around the world on a cruise ship...
A: That's a nice straw man you have there. Let me know when you win the argument with yourself about the flatness of the world...
There are situations where instead of facing argument that makes sense your partner in discussion will accuse you of using 'straw man' tactics.
Now if you combine this with your oponent being a woman (I'm a victim of a brute male now!), you are done.
If the straw man accusation is true, it's really simple to prove you were manouvered into that using quotes from the thread. It'll just become clear and obvious.
Just hysterically yelling there : "Straw Man! Straw Man!" doesn't look serious. You take the response apart and show the dirty tacts not just call names and cry. That's weak.
Of course things like pirating people's software or publicly posting an exploit is going to result in some sort of ban, if not worse! Has human nature and its long history of overreaction just escaped everyone lately?
It's not great, but it's reality. If the only fix available to you is piracy, pirate and go about your business... if they're ignoring the exploit you've reported, making it public isn't nearly as likely to help anyone as it is to turn you into a whipping boy.
Of course, if you don't mind these consequences, go for it. But I don't see how you could possibly fail to foresee the potential backlash.
Did you read the article? He told his boss that he thinks the security badge system had a big flaw. His boss agreed but then fired him. No software was pirated and nothing was publicly posted.
He definitely didn't make the security flaw public though.