RU version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
54% Positive
Analyzed from 1081 words in the discussion.
Trending Topics
#company#blackstone#property#management#security#more#real#companies#researcher#data

Discussion (35 Comments)Read Original on HackerNews
There's nothing wrong with pitching stories this way, but for context, if you look at this researcher's archive, they're all basically "I found a vulnerability in some big company's thingy". The news hook here is literally just "I found a GraphQL bug". This is not Alex Schapiro's most interesting front-page story (by which I mean: they've posted some genuinely interesting stuff before).
Two examples:
1) Hiring 14 year old slaughterhouse workers (https://www.nbcnews.com/news/us-news/pssi-hired-same-child-t...)
2) Gamifying of one its genealogy websites that tracked cemetery markers, which resulted in people "claiming" victims of mass shootings for points (https://dna-explained.com/2022/06/02/find-a-grave-owned-by-a...)
Real estate is very much a closed of group of more traditional business and has not begun to understand their responsibility to keep this data safe.
Edit for more detail: To tack onto this, it's very much the case we're all familiar with where management doesn't care about something being built correctly, they just want it built. Add on top that the management usually has no technical background. Also add that very few engineers that are passionate about writing good software want to stick around at these companies. It's a real nightmare industry.
There are some companies that will give you faith, but they're the occasional large property manager that's been scared shitless about a security based lawsuit (fine by me) or a proptech that's "disrupting" the industry that will be acquired by one of the big dogs in 18 months and slowly eroded away.
I have personally seen real estate people buy some trendy new app based intercom or entry phone system and jam it onto the front of their building and try to require that all of the residents use it...
We seem to lose the concept that people outside of tech have not idea about anything other than whatever they do. Just because you (the royal you) knows the ins/outs of security software does not mean the other 98% of the population does. Yet you're blaming them for buying a tool to do the thing they need help. Blame the devs for being idiots. Don't blame the users.
https://www.beamliving.com/
https://www.npr.org/2021/10/14/1046124278/missouri-newspaper...
Hoping this doesn't happen to you!
If you don’t stand up to weak bullies like that, you end up with people like Trump and Putin in charge.
I know a blackstone company, who were a client of mine before they underwent a hostile takeover (blackstone fired everybody).
They claim to be ISO 27001 certified. They are not. They never removed me from their ISMS, and I can see it has not been touched in three years now.
Wait, it gets worse.
My root credentials still work, both for the app, and for AWS. Nobody has logged into AWS in years (hey, we built a reliable system).
I have unfettered access to highly sensitive (in some cases literally classified) commercial data for the likes of Apple, Siemens, Philips, BAE Systems, Raytheon, and more.
Wait, it gets worse.
They did something to the API endpoint. You can now bypass authentication entirely and anyone has access to this data.
Anyway. Bunch of shysters. Incompetent shysters.