logoalt Hacker News

tptacektoday at 4:55 PM5 repliesview on HN

Beam Living is just the property management company that runs buildings Blackstone owns in New York City. There are thousands of companies like this all over the country and if you poke hard at any of them you will find stuff like this.

There's nothing wrong with pitching stories this way, but for context, if you look at this researcher's archive, they're all basically "I found a vulnerability in some big company's thingy". The news hook here is literally just "I found a GraphQL bug". This is not Alex Schapiro's most interesting front-page story (by which I mean: they've posted some genuinely interesting stuff before).


Replies

ilamonttoday at 8:03 PM

Well, the other notable fact about this story is it's Blackstone, which has a record of giving managers a lot of leeway to do anything to juice the numbers.

Two examples:

1) Hiring 14 year old slaughterhouse workers (https://www.nbcnews.com/news/us-news/pssi-hired-same-child-t...)

2) Gamifying of one its genealogy websites that tracked cemetery markers, which resulted in people "claiming" victims of mass shootings for points (https://dna-explained.com/2022/06/02/find-a-grave-owned-by-a...)

ETA

People have asked about the second example. In a nutshell, Ancestry purchased Find-A-Grave in 2013, and Blackstone acquired Ancestry in 2020.

Originally, Find a Grave was basically used by amateur genealogists to check the names and dates on gravestones across North America. So, if you want to verify Grandma Smith's burial location and other gravestone data three states away, you could search the database for free. Volunteers could submit photos and other data.

Blackstone brought in a Facebook executive to run its genealogy business, and gamified Find A Grave for engagement/revenue purposes (Find A Grave is top of funnel for Ancestry subscriptions and also is heavily blanketed in ad networks.)

Gamification led to some very ugly situations, and as I recall they barely backed down over this. Per Roberta Estes, an experienced genealogist cited above:

The problem is that finding your loved one’s memorial, often with incorrect information, created by a stranger is unexpectedly jarring, at best. Especially to discover that your family member was only a trophy harvest whose memorial was created hours after they died. Then, having to ask (sometimes beg an unresponsive person) for the transfer of their memorial to you, only to have the creator’s name forever associated with the memorial adds insult to injury. ...

Who in their right mind would think that entering those massacred children into Find a Grave immediately was acceptable by any criteria? Any standards of decency? And why would Find a Grave tolerate this for even a minute? Death is traumatic for family members under the “best” of circumstances and it only goes downhill from there.

show 1 reply
bearsyankeestoday at 5:03 PM

Also, as far as I know, no residents were ever alerted that their data was exposed so this also is a bit of a public disclosure angle

show 1 reply
bearsyankeestoday at 5:00 PM

Yeah I hear you but I think this community loves writeups like these -- I personally have learned a TON about how to be an effective security researcher by reading technical writeups others have posted here. Agreed this vuln wasn't a complicated one by any means but I feel like this is the forum for sharing this stuff

show 2 replies
consensus1today at 5:00 PM

There absolutely is everything wrong with implicating a company that has no knowledge of and no responsibility for the breach.

show 1 reply
jordanbtoday at 7:56 PM

I'm glad HN can be counted on to defend Blackstone's good name.

show 1 reply