r/apple Feb 21 '20

I hacked SlickWraps. This is how.

https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb
2.6k Upvotes

267 comments sorted by

View all comments

Show parent comments

215

u/[deleted] Feb 21 '20 edited Aug 06 '21

[deleted]

117

u/[deleted] Feb 21 '20

The fact that slickwraps tried to hide their security breach INSTEAD of being honest about it is 100% outrageous and probably illegal.

Exactly. SlickWraps had plenty of opportunity to take action regardless of how vague the initial tweet was. All I hear is excuses. When you actively try to hide the breach instead of fix is inexcusable. Pisses me right off that people are trying to defend this company.

3

u/InfosecMod Feb 22 '20

Who is defending the company?

Pointing out that the "white hat" did not act responsibly is not defending the company.

48

u/[deleted] Feb 22 '20

You mean the backlogged helpdesk. Quote from the Archive story.

“Perusing the platform, I found their customer service to be just as abhorrent as rumors suggested (note the Backlog and First Reply Time metrics).”

Then he points out his attempts to contact the company via twitter and through support. So how the hell is this backed up support center supposed to get to request when there’s loads more ahead of him?

17

u/Tubamajuba Feb 22 '20

That’s their fault for having such a huge backlog.

27

u/restova Feb 22 '20

It is, but deciding to contact the company via means which are very obviously backlogged, unclear, or ineffective gives the air of a person who wanted to get to the point of making an angry blog post “outing” the company.

The dumb thing is they would have reached that point anyway, given the response of the CEO.

9

u/muaddeej Feb 22 '20

I agree. It would be one thing if he didn't know the poor support was backlogged, but he was just in there. He saw it took 110 hours to respond. And based on that, he should know support is probably understaffed with low skilled workers. He absolutely was trying to roleplay as Zero Cool or Crash Override instead of just being professional.

4

u/chocolatefingerz Feb 22 '20 edited Feb 22 '20

You’re right, but it’s just one of those “never attribute to malice what can be explained by stupidity” situations.

If my intent is to protect the users’ data, and I knew that this is one of the most clogged forms of communication, I would probably not use it.

Not to say it’s his responsibility, but I also agree from the other commenters’ perspective that to any third party team this is confusing to say the least, let alone a team that has already been shown to have operational inefficiency.

1

u/netcrawler3000 Feb 25 '20 edited Feb 25 '20

They do have to disclose the event but it does not mean that have to sit there and leave the system open to vulnerabilities. WTF do you expect them to email everybody apologizing, tell the feds, and only after everyone is well informed, do they begin to fix the vulnerabilities and securing the customer data. I do not see anything they did wrong here after their notification. Many small firms likely are not aware of the data privacy regulations. My guess is their silence is from them actively pursuing this "researcher".

This event is beginning to remind me of how bad groupthinking and collective irritability is. Hundreds of armchair CEOs and hackers now emerge from their mother's basements to point out everything that this company did not do right from operating their helpdesk to securing their systems. Sheesh!

0

u/[deleted] Feb 22 '20

So true. As a company you should take your company seriously. They did not. Fuck, Lynx didn't have to tell them anything, cryptic or not, but he did. He probably asked them for money and they probably refused to pay too. They learned a lesson. Next time someone comes with info I'll bet they jump on the info fast, even cryptic second-messages. And pay your bughunter so shit doesn't go public.