• givesomefucks@lemmy.world
    link
    fedilink
    English
    arrow-up
    57
    arrow-down
    1
    ·
    4 days ago

    Sounds like this guy knows way more than me…

    “It is too much,” Solovewicz says, emphasizing that people shouldn’t assume a domain is unmonitored. “I’m at the point where this would now be a full-time job to handle every single one of these—that’s part of my motivation to talk about this, it is my responsible disclosure. You guys need to fix your systems and not do this and not leak your customer data and your employee data and your own internal data.”

    But couldn’t he just set up an “out of office” so that every single time he gets an email, a response is sent saying:

    Hey bro, this is a real email address, you just sent me stuff you probably shouldn’t. No big deal, but you’re going to keep getting this automated emails. Please fix your security.

    If you get stuck in a loop of automated messages (likely) that’s going to flow a massive flag up at the company, and someone is going to look at it why it’s happening.

    It’s impossible for a human to handle it, but that doesn’t mean it can’t be handled.

    • 🌞 Alexander Daychilde 🌞@lemmy.world
      link
      fedilink
      English
      arrow-up
      21
      ·
      4 days ago

      Anytime you autoreply to email, it means a spammer can spoof the sender and spam you with hundreds of emails, which you will faithfully reply with “This address is not monitored” - but you’re sending those replies out to people who didn’t send them to you, and typically attaching the original message, meaning the spammers get a free spam reflection service from you - you sending their spam to all those people.

      So please don’t use autoresponders.

      • kn33@lemmy.world
        link
        fedilink
        English
        arrow-up
        9
        ·
        4 days ago

        Or only use it on domains with SPF set up for hard fail, and for emails that pass SPF

    • Snapz@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      33
      ·
      4 days ago

      What started out as a personal email project has become a large-scale effort to warn businesses and other groups that they have misconfigured their internal systems and are accidentally sharing sensitive information.

      Traitor…

      • givesomefucks@lemmy.world
        link
        fedilink
        English
        arrow-up
        56
        arrow-down
        1
        ·
        4 days ago

        If a corp is sending your personal information to random email addresses, it is in your best interest for them to stop.

        This person, is trying to get corps to stop, because it’s bad for people.

        They are not trying to save corps at the expense of people, which is what you seem to think is happening

        • Snapz@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          2
          ·
          edit-2
          2 days ago

          If you quietly contract the company, they work to mitigate corporate liability, any benefit to you as user is unintentional. Say it loud and publicly and you empower users to start cleaning up the mess created by company and company gets public shame and pressure to actually fix. Literally no reason to quietly appeal to companies first, both are covered if you go public first

          • givesomefucks@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            2 days ago

            Welp, I feel any future attempt to explain something to you will work out the same…

            And I’m not signing up for that hassle and frustration

            • Snapz@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              2 days ago

              We’re all so lucky to have had the brief moment with you that we did. We’re all devastated by the loss of your future gifts.

              BTW, it’s fine if you bypass the overly dramatic gesture next time and just say, “my mom is home and I don’t want my chicken nuggets to get cold, so I’m going to go now. Bye bye.”

        • Snapz@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          2 days ago

          Because it’s not an accident. And he’s quietly going to the businesses first to try to let them internally address and attempt to cover up and only going public as a last resort.

          As a person, and not a business, his loyalty should be to people. The bully only responds to sunlight.

          • village604@adultswim.fan
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            2 days ago

            You do realize that by telling companies they have vulnerabilities, they’re protecting the people whose information they store, right?

            Do you really want him publicly releasing vulnerabilities so the company gets hacked?

            • Snapz@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              17 hours ago

              You do realize that you can’t go 2 days in modern world without hearing about a giant sensitive dataset being exposed. So yes, more sunlight is needed for any chance of meaningful change These companies can choose to staff up and prioritize sarety, because they don’t do that now obviously. They don’t give a shit and it shows. And they don’t really have to as long as well meaning folks politely do that work for them free of charge - not the IT work, the PR work of sweeping their misdeeds under the rug.