2 comments

  • tptacek 8 minutes ago
    Beam Living is just the property management company that runs buildings Blackstone owns in New York City. There are thousands of companies like this all over the country and if you poke hard at any of them you will find stuff like this.

    There's nothing wrong with pitching stories this way, but for context, if you look at this researcher's archive, they're all basically "I found a vulnerability in some big company's thingy". The news hook here is literally just "I found a GraphQL bug". This is not Alex Schapiro's most interesting front-page story (by which I mean: they've posted some genuinely interesting stuff before).

    • bearsyankees 3 minutes ago
      Yeah I hear you but I think this community loves writeups like these -- I personally have learned a TON about how to be an effective security researcher by reading technical writeups others have posted here. Agreed this vuln wasn't a complicated one by any means but I feel like this is the forum for sharing this stuff
    • consensus1 3 minutes ago
      There absolutely is everything wrong with implicating a company that has no knowledge of and no responsibility for the breach.
  • toomuchtodo 17 minutes ago
    • bearsyankees 8 minutes ago
      yep
      • toomuchtodo 6 minutes ago
        Great work, very detailed vuln report. Its what I'd want to see for triage and remediation.
        • bearsyankees 4 minutes ago
          Thanks!! Just trying to protect other's (and in this case, my own) data :)