HNHacker News
TopNewBestAskShowJobs

JayeLTee

77 karma · joined February 24, 2025

Independent Researcher looking for exposed data online.

You can find me posting about my finds at https://infosec.exchange/@JayeLTee

submissionscomments
JayeLTee··on 'Impossible-to-hack' security turns out to be no security
I just got offered to discuss a "token of appreciation" by another company that included deleting public posts and signing NDAs. I replied saying I don't accept bribes. If that's clear enough for you.

And I didn't say "I will disclose it or you can do X". I asked follow up questions as I always do. Related to intent on notifications to regulators or clients so I can delay my report until the company does their notifications if that is their intent. I've done this multiple times for multiple companies, some I delayed the post for 3-4 months.

I was actually trying to be nice to the company by not doing a disclosure before them, up until this point this was just like every other interaction I have. I sent the information, the server got closed and no one got back to me. None of my communications warranted the reply I got back from this.

JayeLTee··on 'Impossible-to-hack' security turns out to be no security
Although I say:

"This server contains over 3,8GB of data exposed including the logins for 16,500 of your users and a lot of PII and credentials, you need to secure access to the server as soon as possible."

After all that transpired after etc I believe it's possible someone downplayed the severity of this to the CEO and he took that as an opportunity to ignore everything I wrote on the emails and reply that way to me assuming I was some cybersecurity vendor working for "Proton" trying to push something for the company to buy.

JayeLTee··on 'Impossible-to-hack' security turns out to be no security
Motivations are stated after I explain why I'm emailing.

"I'm an independent researcher who posts under the name JayeLTee. I look for publicly exposed data online on my free time and alert the companies affected to try and close the exposure."

There is nothing more than that, want me to make a fairy tale story to tell the companies? I try to be as clear as possible and pass the message as clean as possible with no BS on the email, again because I'm not selling a product or a service.

JayeLTee··on 'Impossible-to-hack' security turns out to be no security
Agreed that the wording to fully understand my intent might not be present on the email and is only achieved when you look at the whole email and what information I provide etc, I've been trying different things to see what works as unfortunately I get ignored totally, A LOT.

That is also the reason there is no direct link to my publications on the actual emails, another link to add suspicion of phishing that leads to being ignored. I do provide a link to my index with all my public finds on the signature of the email though.

Also a google search of my handle which I sign and mention on the email would get multiple hits for reputable news websites such as Databreaches.net, TechCrunch, The Register, Publimetro, but doesn't seem companies do much vetting at all before ignoring the alerts.

JayeLTee··on 'Impossible-to-hack' security turns out to be no security
No I did not query the database after it was fixed.*
JayeLTee··on 'Impossible-to-hack' security turns out to be no security
No I did not query the database after it was exposed.

The information I had was from when the database was publicly exposed.

I don't want to be too specific about the links for the files as I don't know if others accessed this information and could exploit it but they had the website path to download the files exposed on the database, you just needed to know what to add to it, I tried a few things from the information I had and found out they worked.

I would of probably skipped over this, but after their response I wondered if there was more to it.

The files were not stored on the database, they were on a cloud storage but that link made it so no authentication was required to access them (not an expert but would say some hard coded access keys or something similar).

JayeLTee··on 'Impossible-to-hack' security turns out to be no security
The alternative universe can be seen on this post: https://jltee.substack.com/p/lcptrackercom-lcptracker-inc-se...

The company did reach out and said something similar, I held my publication for months months waiting for a reply which they said they would send and ended up finding out their were filing breach notifications to multiple states and never said anything back to me.

JayeLTee··on 'Impossible-to-hack' security turns out to be no security
I think the around 50 public disclosures I did in the last year where I asked 0 times for anything kinda show I'm not looking for any payments.

There is a huge issue regarding publicly exposed data that no one seems to want to acknowledge or talk about, what you see online? It's 100 times worse.

I'm someone who is trying to raise awareness through my finds, nothing else.

Also I was initially polite to the company, not once but twice, as I am to anyone who I reach out, why wouldn't I be? I want them to fix the issues, not ignore me.

Don't expect the politeness to be infinite though, specially when you start accusing me of harassment and lying about the severity of the exposure that affects thousands of people, the ones I DO care about, not the companies.

JayeLTee··on 'Impossible-to-hack' security turns out to be no security
I told him everything he needed to know to fix the exposure on my initial contact on the exact same email I tell him I'm not asking for anything. I even told him some information about the exposed tables.

Backed by the fact that 1 hour after my email, the exposure was closed and the company never replied back to me, it was only after I followed up they emailed all those claims.

Again, I never asked for anything, I even offered to delay my publication so they could notify people if that was their intent, where is the blackmail here?

JayeLTee··on 'Impossible-to-hack' security turns out to be no security
Not a journalist or a reporter, posts aren't meant to be professional. The only reason I even write any of my posts is because companies DO NOT disclose incidents at all, so I have to do it for them.
JayeLTee··on 'Impossible-to-hack' security turns out to be no security
OP here, the one who found the exposed data.

Not sure if you read my 2 emails to the company but I would say I was polite to them and was met with accusations of harassment and straight up lies.

Don't expect me to pat you in the back if you come at me with such claims when I simply alerted you of a security issue.