“It is too much,” Solovewicz says, emphasizing that people shouldn’t assume a domain is unmonitored. “I’m at the point where this would now be a full-time job to handle every single one of these—that’s part of my motivation to talk about this, it is my responsible disclosure. You guys need to fix your systems and not do this and not leak your customer data and your employee data and your own internal data.”
But couldn’t he just set up an “out of office” so that every single time he gets an email, a response is sent saying:
Hey bro, this is a real email address, you just sent me stuff you probably shouldn’t. No big deal, but you’re going to keep getting this automated emails. Please fix your security.
If you get stuck in a loop of automated messages (likely) that’s going to flow a massive flag up at the company, and someone is going to look at it why it’s happening.
It’s impossible for a human to handle it, but that doesn’t mean it can’t be handled.
Anytime you autoreply to email, it means a spammer can spoof the sender and spam you with hundreds of emails, which you will faithfully reply with “This address is not monitored” - but you’re sending those replies out to people who didn’t send them to you, and typically attaching the original message, meaning the spammers get a free spam reflection service from you - you sending their spam to all those people.
What started out as a personal email project has become a large-scale effort to warn businesses and other groups that they have misconfigured their internal systems and are accidentally sharing sensitive information.
If you quietly contract the company, they work to mitigate corporate liability, any benefit to you as user is unintentional. Say it loud and publicly and you empower users to start cleaning up the mess created by company and company gets public shame and pressure to actually fix. Literally no reason to quietly appeal to companies first, both are covered if you go public first
We’re all so lucky to have had the brief moment with you that we did. We’re all devastated by the loss of your future gifts.
BTW, it’s fine if you bypass the overly dramatic gesture next time and just say, “my mom is home and I don’t want my chicken nuggets to get cold, so I’m going to go now. Bye bye.”
Because it’s not an accident. And he’s quietly going to the businesses first to try to let them internally address and attempt to cover up and only going public as a last resort.
As a person, and not a business, his loyalty should be to people. The bully only responds to sunlight.
You do realize that you can’t go 2 days in modern world without hearing about a giant sensitive dataset being exposed. So yes, more sunlight is needed for any chance of meaningful change These companies can choose to staff up and prioritize sarety, because they don’t do that now obviously. They don’t give a shit and it shows. And they don’t really have to as long as well meaning folks politely do that work for them free of charge - not the IT work, the PR work of sweeping their misdeeds under the rug.
Sounds like this guy knows way more than me…
But couldn’t he just set up an “out of office” so that every single time he gets an email, a response is sent saying:
If you get stuck in a loop of automated messages (likely) that’s going to flow a massive flag up at the company, and someone is going to look at it why it’s happening.
It’s impossible for a human to handle it, but that doesn’t mean it can’t be handled.
The domain would get flagged as spam for sending that many emails
Anytime you autoreply to email, it means a spammer can spoof the sender and spam you with hundreds of emails, which you will faithfully reply with “This address is not monitored” - but you’re sending those replies out to people who didn’t send them to you, and typically attaching the original message, meaning the spammers get a free spam reflection service from you - you sending their spam to all those people.
So please don’t use autoresponders.
Or only use it on domains with SPF set up for hard fail, and for emails that pass SPF
Traitor…
…
If a corp is sending your personal information to random email addresses, it is in your best interest for them to stop.
This person, is trying to get corps to stop, because it’s bad for people.
They are not trying to save corps at the expense of people, which is what you seem to think is happening
If you quietly contract the company, they work to mitigate corporate liability, any benefit to you as user is unintentional. Say it loud and publicly and you empower users to start cleaning up the mess created by company and company gets public shame and pressure to actually fix. Literally no reason to quietly appeal to companies first, both are covered if you go public first
Welp, I feel any future attempt to explain something to you will work out the same…
And I’m not signing up for that hassle and frustration
We’re all so lucky to have had the brief moment with you that we did. We’re all devastated by the loss of your future gifts.
BTW, it’s fine if you bypass the overly dramatic gesture next time and just say, “my mom is home and I don’t want my chicken nuggets to get cold, so I’m going to go now. Bye bye.”
“Man attempts to stop corporatuons from leaking data”
“Hey fuck that guy!”
???
Please explain your reasoning for calling him a traitor.
Because it’s not an accident. And he’s quietly going to the businesses first to try to let them internally address and attempt to cover up and only going public as a last resort.
As a person, and not a business, his loyalty should be to people. The bully only responds to sunlight.
You do realize that by telling companies they have vulnerabilities, they’re protecting the people whose information they store, right?
Do you really want him publicly releasing vulnerabilities so the company gets hacked?
You do realize that you can’t go 2 days in modern world without hearing about a giant sensitive dataset being exposed. So yes, more sunlight is needed for any chance of meaningful change These companies can choose to staff up and prioritize sarety, because they don’t do that now obviously. They don’t give a shit and it shows. And they don’t really have to as long as well meaning folks politely do that work for them free of charge - not the IT work, the PR work of sweeping their misdeeds under the rug.