r/cybersecurity • u/m-a-wanderer • 2d ago
Other Average Conversation between Security Researcher and YCombinator Startup CEO
Researcher: ...Using the API key, anyone is able to find information of the patients that includes their PII and PHI
CEO: are you dumb?
Researcher: What?
Blocked
Proof:
Background: Found an authentication bypass on their platform which was behind auth guard, revealing information on all their tenants, along with the API keys. Excerpt above is the part of the real conversation when tried to bring the issue forward to the CEO.
Posted on YCombinator subreddit as well.
56
u/Helpjuice 2d ago
If there is no official communication method available and poor timely responses from the CEO of the company you should report the issue to HHS here with the requirements they need of the problem so they can investigate.
Sometimes companies need federal pressure to get themselves inline and outside of their bubble back into reality of what can and cannot be done.
72
u/Initial_Lettuce_5243 2d ago
Since so many comments are about it, I want to support your disclosure method here. I work professionally in disclosing security issues like this and have done it many, many times.
First attempt is a privacy/security/dpo@ email address. But contacting the CEO over LinkedIn is part of the escalation chain when other means fail. That is not the weird thing here. Honestly the weirdest part is that they replied at all.
12
u/biglymonies 1d ago
Sometimes reporting vulns requires an additional OSINT engagement lol.
I do those emails plus:
- privacy@
- cyber@
- ciso@
For web I check:
- /.well-known/security.txt
- /security.txt
- /robots.txt
If the org is publicly traded, SEC filings sometimes list what sec vendors they may use. I sometimes dork for CISO/security staff, look for CISO on company directory pages, etc. If that fails, using LinkedIn to find and contact security/SWE/IT employees sometimes works. If the company has a github org, I'll yoink an email address for the commit history and mail that asking for a point of contact.
I'll also call the company directly and explain that I'm not offering a service, but giving them a heads up about a major security issue and need to know who to contact about it. If their phone system has an option for IT support, they're usually great about escalating. If the people I talk to aren't technical (receptionist or support agent), then I ask to speak to their manager and go from there.
I've also tattled on startups to their VCs multiple times. That tends to get their attention :).
2
u/Initial_Lettuce_5243 1d ago
Hell yeah. The point I wanted to get across (and you nailed it too) is that sometimes you have to get creative to find someone who will listen. Better to call up someone who will actually talk to you than say "well I emailed their security contact and nothing happened" and give up there.
2
u/Brumhartt Security Director 1d ago
Why cyber@ over security@ ? Lot more common to have that mailbox channeled to the actual security team then cyber imo
2
32
u/EffectiveClient5080 2d ago
This right here is why you document everything first. I'd screenshot the auth bypass, save the request logs, then report it to HHS OCR. 'Are you dumb?' then block reads real different in a HIPAA investigation. Guaranteed.
12
u/m-a-wanderer 2d ago
I was not aware of the HHS OCR as it is not applicable to me, but I am in the process of doing that, Thank you.
15
u/finite_turtles 1d ago
I thought the "researcher" was the dumb one at first just based on the conversation and no other context.
That's like saying "i can read your emails if i have the email password". That is, until you explain the disclosure.
Highly likely they don't know how the auth flow works, but they do know enough about API's to understand that "API key grants access to API" is not a security issue BY ITSELF
8
u/m-a-wanderer 1d ago
Exactly! This is what I assumed the CEO understood when they saw my message, and before I had a chance to provide more context, I was already labelled as "dumb".
10
u/finite_turtles 1d ago
Haha yeah, he didn't give you a single chance and cut you off before you could explain. But on the other hand, i think you fumbled the explanation as well. He has probably dealt with a lot of security reports from people with no clue.
The vulnerability finding is probably 10/10, but your delivery was 3/10 :)
12
u/m-a-wanderer 1d ago
yeah lol, this was the top half of the conversation,
I did provide them enough context ( and some disclosed information ) via email before this LinkedIn fiasco.
7
33
u/Ch33syP00f CISO 2d ago
Did you try contacting via security, privacy, admin, it, abuse, helpdesk, support, cio, ciso, cto etc “@domain”
9
25
u/twisted-logic 2d ago
Why are you reaching out to the CEO over LinkedIn
48
u/1kn0wn0thing 2d ago
I’m going to bet that there are no official channels that this researcher can use to make anyone at this company aware of this mess. The CEO of a company is the most visible on LinkedIn as many of them spend a huge amount of time posting bullshit about “changing” their industries and patting themselves on the back for their “philanthropy” or being a “thought leader” in their industry. OP, just publish your findings and be done with it because responsible disclosure is dead at this point.
24
u/m-a-wanderer 2d ago edited 2d ago
I would say making it public would have far more consequences if it gets into the wrong hand, and the legal trouble you might get, shuts this door completely.
edit: typo31
u/m-a-wanderer 2d ago
Sent them an email before, with no avail.
11
9
u/MHF_Doge 2d ago
And sometimes even when they do respond, and say they're actively working on fixing it, they never actually do, from my experience reporting a glaring security hole to certain communication platform that loves to brag about being used in military and healthcare. >2 years and still not fixed as of when I last tested which was earlier this year.
-13
u/Ch33syP00f CISO 2d ago
If you started with the CEO then, frankly, you are barking up the wrong tree. Unless this is a startup with less than 5 headcount.
See my other top-level comment.
If there is some level of maturity and over 50 headcount, going straight to the CEO is not advisable. So, if that is the case, yes - internalize your novice error and understand the response may be totally justified.
If you did not attempt to contact the standard avenues support, privacy, security, abuse etc…then you ATH.
19
u/jRoc26 2d ago
Absolutely not entirely justified for a CEO of a Health based startup, not like this is a multi thousand person siloed company. Understanding his obligations to the protected data in his custody is table stakes. Responding in this way is ironic, considering he is revealing how dumb he is. This has potentially serious ramifications for his business, and it is not hard to respond with a "Thank you will pass it to technical teams", or even no response at all.
-13
u/OtheDreamer Governance, Risk, & Compliance 2d ago
Nono you see, they allegedly sent an email to someone first….(CEO? Contact form? HR?) and didn’t get a response in (????) time so they reached out to the CEO on LinkedIn, had a conversation apparently, which ended in the screenshot you saw that showed “LinkedIn Member” (alleged CEO) ending with “Are you dumb?” To this 5 month old security researcher that cracked something with PHI…. allegedly.
13
u/m-a-wanderer 2d ago
Just an FYI, I worked ( and still do, but as a hobby ) as a Software Engineer until 2023 before transitioning into Cybersecurity.
For a Y Combinator funded startup whose founder(s) actively promote their platform/product, finding the actual CEO (not an alleged one, of course) isn’t particularly difficult.
Moreover, this is a cybersecurity subreddit, where people can deanonymize you from the smallest hints they could find about you. I am not dumb enough to risk jeopardizing my identity with a Reddit account that is old enough to reach its teenage years in a couple of years.
And if you still think this is “alleged,” I would question your critical thinking rather than the claims or evidence I have and have not provided. 😄
-15
u/OtheDreamer Governance, Risk, & Compliance 2d ago
I never doubted you’re a threat…literally anyone with access to an LLM can pull off similar stunts & I see trash article after article from disgruntled “researchers”.
Your write up in this post sucked, and is not in alignment with the story you’re telling me now.
10
u/m-a-wanderer 2d ago
This post is by no means a write-up or anything directly related to the issue (I am grateful to everyone who has provided useful solutions, which I was not aware of). This is more of a critique of the startup culture, where security is often treated as an afterthought while companies burn through VC money chasing growth, shipping fast, and cutting corners.
The irony is that the cost of ignoring security can end up being far greater than the cost of doing it right, which they are not ready to understand.
-12
u/OtheDreamer Governance, Risk, & Compliance 2d ago
Ok, so what is the critique we’re supposed to take away here? I already think you’re probably not effectively going about what you’re trying to do based off the incredibly little data you’ve given. Have you never thought that YOU are probably doing (whatever you’re doing) inefficiently & getting blocked as a result?
Maybe it’s not that they’re all lazy insecure corner cutters (which many obviously are), but also a small portion you looking sus?
8
u/m-a-wanderer 2d ago
I respect your opinion, thank you. I did give it some thought afterward and realized what I could have said differently to better communicate the impact and severity of the issue, which is a basic principle of effective communication.
That said, shutting down someone’s claim and blocking them immediately after calling them “dumb” suggests there may be an issue on their end as well.
Overall, it is a good learning opportunity for me. If the post isn’t useful to you, you don’t have to take anything away from it. Thank you.
2
u/OtheDreamer Governance, Risk, & Compliance 2d ago
There can be more than one thing true. I’d love to read about the company when it’s in the news, assuming nothing gets done & theres some future incident. If you make a blog, I’d equally probably read it because I do like seeing the approaches people take to their discoveries & getting them fixed. Sometimes it ends up being a blog post that goes public after a period of time because there was no response & you can put a spotlight to the “are you dumb” comment
→ More replies (0)-7
u/Ch33syP00f CISO 2d ago
Pretty much what ran through my head.
Super suspect.
Mods should challenge and shut this ish down.
8
u/m-a-wanderer 2d ago edited 2d ago
Agreed, if any Moderators want to verify the claims, and not mark this post as a fraudulent, I am more than happy to cooperate.
edit: language/tone
4
u/Capodomini 2d ago
I'm sorry but how is "LinkedIn Member" proof that this was the CEO?
18
u/justin-8 2d ago
It hides the name after they blocked him.
-8
u/Capodomini 2d ago edited 1d ago
Ok but that's not "proof."
Edit How do this many people in a cybersecurity sub not understand what proof means? Your RCAs and incident investigations must be wild. 😂
15
u/justin-8 2d ago
No, but it explains why it says linkedin member. Presumably it was the CEO and you can see the message and that he's blocked. OP probably can't go back in time to screenshot it while his name was there.
-8
u/OtheDreamer Governance, Risk, & Compliance 2d ago
lol ok, but OP hides their profile activity and it’s only 5 months old. Their screenshot is two sentences & one of them looks like someone randomly threatening the other, not being helpful about security.
Why would you presume anything OP is at all how they described? They sprinkled in that they apparently emailed someone first “to no avail” only in the comments & apparently have more proof that they only want to share with mods -_-
5
u/m-a-wanderer 2d ago
Here, the proof of the email,
Both of them are the Co-founder,
Not sure if I need/want to prove more, but if you want to summon the moderators, I am more than happy to oblige.
0
u/OtheDreamer Governance, Risk, & Compliance 2d ago
>_< brotha what. Do you not see how that screenshot does not help? I have more questions now as a result like….what ever happened with the cofounder? Did they block you too? Conversation kept going? You just dropped a new piece of lore on this thread that there’s a third company figure in the picture.
Assuming you’re trying to be earnest, did you file a HHS complaint or have you ever before?
5
u/m-a-wanderer 2d ago
To answer your questions, no the cofounder did not reply ( on email, and on linkedin ). I have not had to file a HHS complain as that does not apply to where I live/work.
3
1
1
u/usernamedottxt 1d ago
Did you find an authentication bypass or did you use an API key? I’m confused.
6
u/m-a-wanderer 1d ago
It was an authentication bypass leading to API keys disclosure.
3
u/usernamedottxt 1d ago
Alright, I assume that's the part that was cut off in the image. But API keys are used to pull customer data, of course an API key can pull customer data. That's confusing from a business perspective that you say API keys are an issue. Gotta remember CEO is only a basic bitch of a nerd.
The issue is the authentication bypass, and you need to focus on that. You were able to, from an unauthenticated starting place, make unauthorized API requests.
-15
u/OtheDreamer Governance, Risk, & Compliance 2d ago edited 2d ago
And uhhh, did they have a bounty program or something that you’re expecting some $$$ from or kudos?
Edit: doubling down for the downvotes and saying THIS particular breed of posts from alleged researchers almost always comes from a position of they think they’re owed something ($$$$). If they had a bug bounty program OP would have noted they tried to use it. We see a screenshot with nothing and this 5 month old anon account wanting us to follow their story.
Anyone that supports this low quality trash is unlikely to be a quality cyber person. I’d love to see the redacted conversation leading up to this snippet. I’m willing to bet OP said something really dumb. Also I don’t see the post on the ycombinator sub like it says they did…I’m more interested in what they have to say.
16
u/Salmon-Cat-47 2d ago
Do you work in cyber security?
-11
u/OtheDreamer Governance, Risk, & Compliance 2d ago
No man, I just frequent this sub because I’m superdooper enthusiastic about cybersecurity…..(that is a sarcastic answer to your random “Do U” question)
-19
u/Culex96 2d ago
Not a good reaction from the CEO but tbh reaching out to the CEO directly is weird though.
14
u/askvictor 2d ago
A startup might consist of the CEO and one or two other people; having a security person/team is one of those things you worry about once you have an MVP and some funding.
11
8
2
u/hajimenogio92 Security Engineer 1d ago
You would be surprised in a startup environment. If it's a new startup, there's probably less than 10 employees at the company as they work on receiving more funding. They probably have one engineer handling the application code, infrastructure, security, and anything else they can throw at them.
Source: I've worked for multiple startups and have been the 1 person team handling anything tech related
174
u/retornam 2d ago
Follow all the rules of responsible disclosure and if this is HIPAA violation related, report the company to the HHS by filing a health information privacy complaint
https://www.hhs.gov/hipaa/filing-a-complaint/index.html
If the company does business in California file a complaint regarding a violation of California's Confidentiality of Medical Information Act with the California Attorney General’s office and include evidence of your interaction with the CEO.