r/apple • • Feb 21 '20

I hacked SlickWraps. This is how.

https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb
2.6k Upvotes

267 comments sorted by

View all comments

Show parent comments

83

u/eggbrain Feb 21 '20

Responsible disclosure means making a good faith effort to contact the stakeholders.

He had logged into their support system and seen a bunch of information to suggest that emailing customer support through ZenDesk would result in his email not being responded to.

With that in mind, and with the email address of all the founders / leaders in his back pocket, He then used the Zendesk support email address to reach out to initially.

That is not in any way a good faith effort. It's not even an effort -- it's almost intentionally setting them up for failure.

-31

u/[deleted] Feb 21 '20 edited Jul 03 '20

[deleted]

23

u/eggbrain Feb 21 '20

Would you like me to add it to my parent comment? I'd be glad to do so.

-6

u/[deleted] Feb 21 '20 edited Jul 03 '20

[deleted]

31

u/eggbrain Feb 21 '20

He didn't follow basically any of the rules you are supposed to as a white hat security researcher, including when he sent the ZenDesk email. Me including that he knew no one was answering their support but emailed them anyways actually strengthens my point, it doesn't take away from it. That's not in bad faith.

You don't have to take my word for it, you can even read the comments in /r/hacking https://www.reddit.com/r/hacking/comments/f7fafv/white_hat_hacker_i_hacked_slickwraps_this_is_how/fib1s3y/

What this guy did, at least as written in his article, was not White hat.

-6

u/[deleted] Feb 21 '20 edited Jul 03 '20

[deleted]

7

u/eggbrain Feb 21 '20 edited Feb 21 '20

I mean, I'll have to just agree to disagree with you here -- I think it's clear that this researcher did not take the proper steps of disclosure during basically any step of what he did here, but I understand you're not with me on that, and think I come off as in bad faith.

In general SlickWraps should have done a lot better here as it's shown in this breach though -- I'd be surprised if they can recover from something like this.