HNHacker News
TopNewBestAskShowJobs

clobec

2 karma · joined January 2, 2015

submissionscomments
clobec··on Moonpig.com Vulnerability – Exposes customer data
Why are you saying the fault lies with the vendor? Do you think nobody knows that? Do you think that's not obvious? Do you think that's what I was commenting about?

There's a difference between reading and comprehension.

clobec··on Moonpig.com Vulnerability – Exposes customer data
Have you read any of the above?

It's clear they didn't care, that's why I'm saying the ICO should have been informed. That would force them to give a shit.

clobec··on Moonpig.com Vulnerability – Exposes customer data
I still don't see why he had to do this?

He has plenty of time to inform the ICO of this issue. He contacted moonpig then let the sit on this for a year.

If he wants to be a disclosure hero, he could have at least told the ICO at the same time he told moonpig.

The issue is 100% Moonpigs fault but he chose to disclose publicly rather than use the legal route set up to deal with these kinds of issues.

The whole responsible disclosure scene needs a reboot and people need educating on the responsible way to deal with these issues. Public disclosure should be a last resort (within reason). Not even contacting the ICO before doing this is shocking to me.

clobec··on Moonpig.com Vulnerability – Exposes customer data
Moonpig is UK based. He could have looked up how to report a data breach in the UK.

Not sure what the DMCA reference is about. I understand that people use DMCS on companies that are not US based therefore it has no power. Still not sure why you mentioned that though.

clobec··on Moonpig.com Vulnerability – Exposes customer data
> You're getting mad at the wrong person here, full stop.

No I'm not. I;m not angry. I realise this is the fault of Moonpig

>This is gross, inexcusable negligence and incompetence. I'm surprised this guy didn't wait more than a few months, given the severity of this problem.

I agree

>Riiiight. Do you honestly think something this basic wouldn't be discovered by criminals soon, if not already?

We don't know if anyone has already used this. We don't know if anyone ever knew about his. But now we know everyone knows about it. To be honest, I would not be surprised if someone may have already used this for nefarious purposes but at this point in time there doesn't seem to be a public dump of data for low skilled hackers to continue using for years to come.

I still think this should not have been publicly disclosed in this manner. He did not contact the ICO and he left this exploit open for a year because he didn't know the mature way to handle this.

clobec··on Moonpig.com Vulnerability – Exposes customer data
I don't disagree with you but I still think I have a good point.

He should have gone to the ICO straight away as well as report directly to moonpig then if it wasn't fixed within x amount of time, take next escalation step (which may or may not be public disclosure). Given that it's midnight in the UK now, we're lucky that they acted so quickly (assuming the offline API isn't just scheduled downtime).

Going public had no guarantee that would have taken the API offline. I guess taking risks like that is easy when it's now your own data that's being compromised....

clobec··on Moonpig.com Vulnerability – Exposes customer data
In my other comment, I said the ICO should have been the first place this was reported rather than putting it on the net for opportunistic bad actors to dump all their customer data in pastebin.....
clobec··on Moonpig.com Vulnerability – Exposes customer data
This is irresponsible disclosure. You should have contacted the information commissioners office. They would have used legal powers to force Moonpig to rectify this. There are very steep penalties for not protecting customer data.

Now that you've publicly disclosed this, opportunists (people one level above script kiddies) will probably grab a data dump and compromise every customer.

Dealing with this via legal channels would have ensured a resolution whilst protecting customer data from any opportunistic bad actor.

Shame on you. I can't wait for myself and my wife to get doxxed now. Thanks.

Also, FYI; the whole card number isn't returned because they are probably tokenising the full card number with their payment gateway.... Or at least, I hope.

DOWNVOTING because you don't agree with me? How rude. I believe I'm a making a valid point, there are legal channels in place to help with this sort of thing.

EDIT. someone people think I do no hold moonpig responsible for this. I do! I am not blaming the security researcher. What I am saying is that some countries (like the one where moonpig is incorporated and operates) have agencies that deal with issues like these. Getting these agencies involved before public disclosure is a much nicer way to deal with these sorts of issues.

I'm aware that this exploit may already have been used but that doesn't mean that we should tell everyone about it until it is resolved. Getting the ICO involved may have resolved this issue a long time ago.

My disclosure - I have a friend that works at the ICO and she tells me that these issues usually take them (on average) 2 months to sort out. COmpanies get very anxious when the ICO contact them.

clobec··on The Software Developer's Sketchbook
This is so laughable and a little typical of HN.

I've worked with guys that have done nothing other than Spring and Hibernate for nearly a decade and they know those platforms inside and out. There's just no way someone junior with a few hobby projects are running rings around those guys in their areas.

However, if you take something new, or something these guys haven't used, then yea.... rings could be run. Other than that, I don't think so.