7 comments

  • tptacek2 hours ago
    Beam Living is just the property management company that runs buildings Blackstone owns in New York City. There are thousands of companies like this all over the country and if you poke hard at any of them you will find stuff like this.<p>There&#x27;s nothing wrong with pitching stories this way, but for context, if you look at this researcher&#x27;s archive, they&#x27;re all basically &quot;I found a vulnerability in some big company&#x27;s thingy&quot;. The news hook here is literally just &quot;I found a GraphQL bug&quot;. This is not Alex Schapiro&#x27;s most interesting front-page story (by which I mean: they&#x27;ve posted some genuinely interesting stuff before).
    • bearsyankees2 hours ago
      Also, as far as I know, no residents were ever alerted that their data was exposed so this also is a bit of a public disclosure angle
    • bearsyankees2 hours ago
      Yeah I hear you but I think this community loves writeups like these -- I personally have learned a TON about how to be an effective security researcher by reading technical writeups others have posted here. Agreed this vuln wasn&#x27;t a complicated one by any means but I feel like this is the forum for sharing this stuff
      • dylan60419 minutes ago
        But as GP stated, if as a security researcher you discover this as Company X using Company Y&#x27;s product that has the vuln but your write up lays the blame at Company X&#x27;s feet leaves a lot to be said about your skillz as a researcher. If you wrote it up as Company Y&#x27;s product has a vuln and is used in this market by companies like X you&#x27;d sound like a much more skilled researcher.
      • tptacek2 hours ago
        Yeah, you&#x27;re totally fine.
    • consensus12 hours ago
      There absolutely is everything wrong with implicating a company that has no knowledge of and no responsibility for the breach.
      • tptacek2 hours ago
        You mean the Blackstone namedrop? I had the same reaction. Beam is an internal division of Blackstone, for whatever that&#x27;s worth, but I don&#x27;t think there&#x27;s a news hook <i>about Blackstone</i> here. This is, like, every property management company everywhere, whether indie or corporate.
        • bearsyankees2 hours ago
          If this is the case then IMO all the more reason to publicize it -- my SSN shouldn&#x27;t be exposed just because I applied for a lease [ and we shouldn&#x27;t just brush that off as something that is a given ]
          • tptacek2 hours ago
            I mean, that&#x27;s true, and I&#x27;m not saying there&#x27;s anything misleading about the post, just that this is true of basically all the companies that do this. All I&#x27;m saying is that there isn&#x27;t a meaningful Blackstone hook here.
            • antonvs1 minute ago
              &gt; this is true of basically all the companies that do this<p>Evidence?
            • DANmode2 hours ago
              If you’re too big to manage your subsidiaries, don’t buy them&#x2F;build them.<p>This is no different than blaming the big AI tool because it messed up doing work in your spaghetti codebase - “how else was I supposed to do it?”.<p>Stay small enough to do business properly.<p>Yes, this is a ding on the parent company.<p>How indicative it is of their other companies making the exact same mistakes is a different question.<p>But I’d expect issues <i>somewhere</i>.
              • tptacek1 hour ago
                Beam Living manages giant high-rise housing developments in New York City. It&#x27;s not a mom-and-pop problem space, unless you&#x27;re for some reason opposed to density.
                • DANmode15 minutes ago
                  I’m opposed to using your scale as an excuse to be an incompetent.<p>It’s one of the major ethical &#x2F; effectiveness issues with business - especially American business - today.
                  • tptacek9 minutes ago
                    You&#x27;d much rather rent from someone like Beam Living than a mom-and-pop operator that owns a small apartment building. Things will get fixed, and you&#x27;ll get most of your security deposit back.
        • jimbo892 hours ago
          Beam is actually a little bit unique here. They have a spent a lot of money building a lot of custom software that most other property managers just buy off the shelf.
        • consensus11 hour ago
          Yes, that&#x27;s what I meant, but I thought your comment meant that it was a property management company hired by Blackstone, not an internal division of Blackstone. That changes things completely.
  • jjice2 hours ago
    I work for a company building real estate adjacent software and have worked on connections to all the major property management systems and large (and small) proptech companies. I can tell you that at least 90% of them have some of the worst security practices you&#x27;ve ever seen. Many of the largest property management systems allow a third-party vendor to export your Social Security number and date of birth, and most property managers I&#x27;ve seen don&#x27;t bat an eye at giving up as much information as their vendor requests (which they usually don&#x27;t need).<p>Real estate is very much a closed of group of more traditional business and has not begun to understand their responsibility to keep this data safe.<p>Edit for more detail: To tack onto this, it&#x27;s very much the case we&#x27;re all familiar with where management doesn&#x27;t care about something being built correctly, they just want it built. Add on top that the management usually has no technical background. Also add that very few engineers that are passionate about writing good software want to stick around at these companies. It&#x27;s a real nightmare industry.<p>There are some companies that will give you faith, but they&#x27;re the occasional large property manager that&#x27;s been scared shitless about a security based lawsuit (fine by me) or a proptech that&#x27;s &quot;disrupting&quot; the industry that will be acquired by one of the big dogs in 18 months and slowly eroded away.
  • walrus012 hours ago
    My biggest take away from this is not really anything about the specific security vulnerability, but rather that real estate industry people will buy any SaaS product without research or any due diligence.<p>I have personally seen real estate people buy some trendy new app based intercom or entry phone system and jam it onto the front of their building and try to require that all of the residents use it...
    • dylan60413 minutes ago
      What would you expect them to do? They&#x27;re in real estate. They&#x27;re not coders. Sure, they could hire a company to evaluate choices and let them know, but they&#x27;re so not coders how would they even know that&#x27;s something that can be done? Also, how much time would that add to getting off of a spreadsheet that gets emailed to people each time it&#x27;s updated?<p>We seem to lose the concept that people outside of tech have not idea about anything other than whatever they do. Just because you (the royal you) knows the ins&#x2F;outs of security software does not mean the other 98% of the population does. Yet you&#x27;re blaming them for buying a tool to do the thing they need help. Blame the devs for being idiots. Don&#x27;t blame the users.
  • toomuchtodo2 hours ago
    Beam Living<p><a href="https:&#x2F;&#x2F;www.beamliving.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.beamliving.com&#x2F;</a>
    • bearsyankees2 hours ago
      yep
      • toomuchtodo2 hours ago
        Great work, very detailed vuln report. Its what I&#x27;d want to see for triage and remediation.
        • bearsyankees2 hours ago
          Thanks!! Just trying to protect other&#x27;s (and in this case, my own) data :)
  • lacoolj1 hour ago
    I&#x27;m glad you did this, but be careful man. Dudes have been prosecuted (right? wtf?) for way less:<p><a href="https:&#x2F;&#x2F;www.npr.org&#x2F;2021&#x2F;10&#x2F;14&#x2F;1046124278&#x2F;missouri-newspaper-security-flaws-hacking-investigation-gov-mike-parson" rel="nofollow">https:&#x2F;&#x2F;www.npr.org&#x2F;2021&#x2F;10&#x2F;14&#x2F;1046124278&#x2F;missouri-newspaper...</a><p>Hoping this doesn&#x27;t happen to you!
  • josefritzishere2 hours ago
    What a trashfire of a company. Where are the legal penalties for such reckless behavior?
  • madaxe_again2 hours ago
    Hah. This is nothing.<p>I know a blackstone company, who were a client of mine before they underwent a hostile takeover (blackstone fired everybody).<p>They claim to be ISO 27001 certified. They are not. They never removed me from their ISMS, and I can see it has not been touched in three years now.<p>Wait, it gets worse.<p>My root credentials still work, both for the app, and for AWS. Nobody has logged into AWS in years (hey, we built a reliable system).<p>I have unfettered access to highly sensitive (in some cases literally classified) commercial data for the likes of Apple, Siemens, Philips, BAE Systems, Raytheon, and more.<p>Wait, it gets worse.<p>They did something to the API endpoint. You can now bypass authentication entirely and <i>anyone</i> has access to this data.<p>Anyway. Bunch of shysters. Incompetent shysters.
    • lightedman50 minutes ago
      If what you say is true a report to ISO themselves will strip their certifications away and make them toxic to other businesses.