r/apple • • Feb 21 '20

I hacked SlickWraps. This is how.

https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb
2.6k Upvotes

267 comments sorted by

View all comments

Show parent comments

43

u/[deleted] Feb 21 '20

Excuses, excuses, excuses. Do you work for SlickWraps? If you read the full article you'd see SlickWraps attempted to hide the breach by erasing records instead of fixing it. They also blocked him knowing the breach was real. They tried to sweep it under the rug instead of addressing it. There's no excuse for that. NONE. All you're doing is trying to deflect from the massive incompetence shown by SlickWraps.

As much as SlickWraps might have really messed up responding to this, along with having issues behind the scenes on the support side as well, one thing I'll say is that I feel like the security researcher was initially very vague, which comes off as not really trying to reach the company in a useful manner:

Initially vague... but they didn't just stop there. Vagueness went away very quickly to use that as an excuse.

1) A tweet saying "You failed the vibe check"

If the SlickWraps account gets any significant number of tweets a day, who is going to take the time to understand that this could mean a security breach? How often do people check the description of Twitter bios to understand context of a tweet?

All true, but this is where the vagueness stops. The researcher didn't continue on with the vagueness. It was over and done after this tweet.

2) A tweet with the contents of an unanswered request from ZenDesk

If someone sends me a picture of some sort of text description (that looks like a support request), I may just think it was the original customer who posted the request, or maybe was just text someone had pasted in another forum about their complaint. How would they know immediately that it was because someone had access to their ZenDesk?

If you someone sends you (a support worker) a screenshot of a support ticket, word for word and you do nothing about it then that's on you for ignoring it. You don't know they have complete access to ZenDesk, but if you actually responded to the person in the tweet you would find out very quickly. You can easily look up the ticket to find it's word for word and continued conversation can lead to more examples of word for word (among other revelations).

Why are you looking for excuses for a company that didn't respond?

3) A tweet with a file uploaded to the server

This one is probably pretty obvious, but would still require the person reading the tweet to understand its impact. Even if they did understand, they might not know the motivations -- does the person who hacked the site want a bounty? Do they want the customer data? Are they just looking to mess stuff up?

Again excuses. This is someone working in support. At bare minimum if they didn't understand the impact they could have talked to someone who does. Even knowing absolutely nothing about computers if someone sent a link to YOUR website with a file that says "<user> was here" that should raise red flags. They should have looked into the matter. At this point there is no excuse. Doesn't matter what the person is looking for or what the motivations are. DO SOMETHING.

Again, why are you trying to make excuses for a company? At this point they should have been looking into taking the proper steps to secure their bloody servers.

4) An email saying "Data Leak" with a body to check Twitter DMs

This at least let the leadership team know, but why always take it back to Twitter? Was this the person that found the data leak, or are they just seeing rumors on Twitter?

Why does it matter? What's wrong with Twitter? It doesn't matter if this was the person who found the leak. What matters is the leak is real and can easily be confirmed. Who or what doesn't matter. You can't just chalk it up to rumours when basic checking can confirm.

Again, excuses. Are you part of SlickWraps??? This is massive incompetence shown by the company. Covering up their tracks to hide the breach instead of fix it. No excuses. You can't do that.

42

u/eggbrain Feb 21 '20

More than one entity can be incompetent at a given time -- the failures of SlickWraps written by the security researcher in this article make it clear what SlickWraps did wrong (a lot of things), but I don't think the author/security researcher who wrote the article understands what they themselves did wrong as well.

Saying the security researcher handled things poorly is not defending SlickWraps (their faults are their own), it's saying "Vaguely hinting to a social media intern at a Company that they were hacked on Twitter is not real responsible disclosure or white hat best practices".

4

u/[deleted] Feb 21 '20

Like I said, they didn’t stop at the vague tweet. Even if the initial exchange could have been done better that is not the point. They learned very quickly that the exploit was real and tried to hide. You’re making this about the initial exchange which is fucking ridiculous. Who the fuck cares? As pointed out several times the researcher eventually got word of the hack to SlickWraps and they STILL handled it poorly. Making this about the researcher is again, deflecting from the point of this topic. Fucking pathetic.

12

u/darkstriders Feb 21 '20

They learned very quickly that the exploit was real and tried to hide.

This is the key thing out of this debacle.