Beam Living is just the property management company that runs buildings Blackstone owns in New York City. There are thousands of companies like this all over the country and if you poke hard at any of them you will find stuff like this.
There's nothing wrong with pitching stories this way, but for context, if you look at this researcher's archive, they're all basically "I found a vulnerability in some big company's thingy". The news hook here is literally just "I found a GraphQL bug". This is not Alex Schapiro's most interesting front-page story (by which I mean: they've posted some genuinely interesting stuff before).
Well, the other notable fact about this story is it's Blackstone, which has a record of giving managers a lot of leeway to do anything to juice the numbers.
People have asked about the second example. In a nutshell, Ancestry purchased Find-A-Grave in 2013, and Blackstone acquired Ancestry in 2020.
Originally, Find a Grave was basically used by amateur genealogists to check the names and dates on gravestones across North America. So, if you want to verify Grandma Smith's burial location and other gravestone data three states away, you could search the database for free. Volunteers could submit photos and other data.
Blackstone brought in a Facebook executive to run its genealogy business, and gamified Find A Grave for engagement/revenue purposes (Find A Grave is top of funnel for Ancestry subscriptions and also is heavily blanketed in ad networks.)
Gamification led to some very ugly situations, and as I recall they barely backed down over this. Per Roberta Estes, an experienced genealogist cited above:
The problem is that finding your loved one’s memorial, often with incorrect information, created by a stranger is unexpectedly jarring, at best. Especially to discover that your family member was only a trophy harvest whose memorial was created hours after they died. Then, having to ask (sometimes beg an unresponsive person) for the transfer of their memorial to you, only to have the creator’s name forever associated with the memorial adds insult to injury. ...
Who in their right mind would think that entering those massacred children into Find a Grave immediately was acceptable by any criteria? Any standards of decency? And why would Find a Grave tolerate this for even a minute? Death is traumatic for family members under the “best” of circumstances and it only goes downhill from there.
It's Find-a-Grave, an indie genealogy site that was acquired by Ancestry, which itself was acquired by Blackstone sometime in the last decade. Blackstone brought in an ex-Facebook executive to run it, and this was one of the results.
Right so the premise here is that somewhere high atop 345 Park Avenue a Blackstone executive is twirling his mustache while saying "gamify the gravesites". Seems implausible. Ancestry was not a good company to begin with (you know what organization really does a good job of this, by the way? The Latter Day Saints), and this is fully on brand for them.
> somewhere high atop 345 Park Avenue a Blackstone executive is twirling his mustache while saying "gamify the gravesites".
I don't think so.
It's more like "hit the numbers no matter what, we don't care what you do to hit them." They hire managers that are ruthless about following through. IMHO this style of ownership is more likely to lead to otherwise avoidable situations involving lax security, teenaged slaughterhouse workers, and trophy hunters on genealogy sites.
It has to be 18 months after public disclosure before the company has to send out a letter letting them know that someone might use their information, and they are eligible for yet another free credit monitoring service......
Yeah I hear you but I think this community loves writeups like these -- I personally have learned a TON about how to be an effective security researcher by reading technical writeups others have posted here. Agreed this vuln wasn't a complicated one by any means but I feel like this is the forum for sharing this stuff
But as GP stated, if as a security researcher you discover this as Company X using Company Y's product that has the vuln but your write up lays the blame at Company X's feet leaves a lot to be said about your skillz as a researcher. If you wrote it up as Company Y's product has a vuln and is used in this market by companies like X you'd sound like a much more skilled researcher.
You mean the Blackstone namedrop? I had the same reaction. Beam is an internal division of Blackstone, for whatever that's worth, but I don't think there's a news hook about Blackstone here. This is, like, every property management company everywhere, whether indie or corporate.
If this is the case then IMO all the more reason to publicize it -- my SSN shouldn't be exposed just because I applied for a lease [ and we shouldn't just brush that off as something that is a given ]
I mean, that's true, and I'm not saying there's anything misleading about the post, just that this is true of basically all the companies that do this. All I'm saying is that there isn't a meaningful Blackstone hook here.
Beam Living manages giant high-rise housing developments in New York City. It's not a mom-and-pop problem space, unless you're for some reason opposed to density.
You'd much rather rent from someone like Beam Living than a mom-and-pop operator that owns a small apartment building. Things will get fixed, and you'll get most of your security deposit back.
Personally, I've always had a better experience dealing directly with small time landlords than with property managers. For a start, they have been less likely to raise rents at every opportunity. I also prefer when my money goes to someone in my community/local area.
I've never once gotten a security deposit back from a mom-and-pop landlord without forcing the issue legally, and I did an informal poll of acquaintances last year and we had never even heard of that happening. Unlike mom-and-pops, corporate property managers just do what they say they're going to do.
That sucks. Maybe it's a cultural thing or due to different regulations (I'm not in North America)?
Anyhow, all else being equal, so long as I am living in a transactional society, I prefer those transactions to be with people I actually know. I like real relationships. So much of the way we are changing as a society seems to be alienating us from each other - I make a point of trying to counter that in my daily life.
Oh, yeah, for sure, I'm making confident assertions exclusively about American rental norms. I have no idea if corporate property management in Europe is better or worse than independent building owners. All I know is that renting is much more normalized there than it is here, where renters are considered a second-class state of residency that one expects to graduate from into full ownership as soon as possible.
On the flip side, corporate PMs tried billing my friends for damage that was questionable/grasping at best on an apartment they'd told my friends, in writing, that was going to be gutted down to the studs on the expiry of their lease.
The largest corporate PM in my county has this "look how tenant-friendly we are, we won't raise your leases just because we can" all happy and smiley website where they advertise their open listings...
... and a much less advertised site dedicated just to property owners where they "promise to get you the maximum value out of your investment, looking for every opportunity to maximize its income-earning potential (i.e. raise rents at every possible opportunity to the maximum legally allowed), and "ensuring that when you do change tenants, the minimum effort and cost is required" (i.e. bill your previous tenants for as much of their security deposit as possible, while doing as little as possible).
This led to situations where my partner and I saw that the "inspection form" for the apartment we'd left not twenty minutes prior (it was initially meant to be previously) was sitting on the desk of the property manager filled with remarks like "blinds not cleaned, needed professional cleaning", "drywall holes, needed professional repair", "odors, needed remediation, professional cleaning".
In other words, they'd planned ahead to take the deposit, and when our meeting with the PM was rescheduled it pointed out the lie, "Oh, when was this inspection and these repairs all done? In the fifteen minutes since us locking the door and going down the elevator to wait for you in the lobby?" Of course, said PM company also owned, helpfully, a carpet cleaning company, a housecleaning company, and everything else, so you knew they were going to give you a good deal (not).
"Oh... um... oops... that's a mistake, I must have printed off from a template and not tidied it up".
Beam is actually a little bit unique here. They have a spent a lot of money building a lot of custom software that most other property managers just buy off the shelf.
Yes, that's what I meant, but I thought your comment meant that it was a property management company hired by Blackstone, not an internal division of Blackstone. That changes things completely.
That's not what I'm doing, but if you want me to, I'll bite, because Blackstone does more for housing than activists do (if you measure housing outcomes in terms of how many people end up housed, as opposed to whether or not the "right" people get to live in the "right" neighborhoods).
I think the expectation on a message board is that you can name drop a big private equity firm and count on voting support for them. Unfortunately for you, I've spent the last 5 years working on rolling back single-family zoning in my municipality, and an alarming amount of that work has involved pushing back on NIMBYs arguing that if we allow housing construction Blackstone (very specifically Blackstone) will just come snap all the real estate up and hoard it.
So I've had some time to marinate in this particular bit of populist rhetoric.
I work for a company building real estate adjacent software and have worked on connections to all the major property management systems and large (and small) proptech companies. I can tell you that at least 90% of them have some of the worst security practices you've ever seen. Many of the largest property management systems allow a third-party vendor to export your Social Security number and date of birth, and most property managers I've seen don't bat an eye at giving up as much information as their vendor requests (which they usually don't need).
Real estate is very much a closed of group of more traditional business and has not begun to understand their responsibility to keep this data safe.
Edit for more detail: To tack onto this, it's very much the case we're all familiar with where management doesn't care about something being built correctly, they just want it built. Add on top that the management usually has no technical background. Also add that very few engineers that are passionate about writing good software want to stick around at these companies. It's a real nightmare industry.
There are some companies that will give you faith, but they're the occasional large property manager that's been scared shitless about a security based lawsuit (fine by me) or a proptech that's "disrupting" the industry that will be acquired by one of the big dogs in 18 months and slowly eroded away.
My biggest take away from this is not really anything about the specific security vulnerability, but rather that real estate industry people will buy any SaaS product without research or any due diligence.
I have personally seen real estate people buy some trendy new app based intercom or entry phone system and jam it onto the front of their building and try to require that all of the residents use it...
What would you expect them to do? They're in real estate. They're not coders. Sure, they could hire a company to evaluate choices and let them know, but they're so not coders how would they even know that's something that can be done? Also, how much time would that add to getting off of a spreadsheet that gets emailed to people each time it's updated?
We seem to lose the concept that people outside of tech have not idea about anything other than whatever they do. Just because you (the royal you) knows the ins/outs of security software does not mean the other 98% of the population does. Yet you're blaming them for buying a tool to do the thing they need help. Blame the devs for being idiots. Don't blame the users.
No charges were filed in that case. It was just an out-of-control, weak, stupid, and corrupt governor - Mike Parsons - abusing his power to try to cover up his ignorance and his administration’s incompetence.
If you don’t stand up to weak bullies like that, you end up with people like Trump and Putin in charge.
Mike Parson is a dumb, racist boomer in a state full of them. He was a trump clone that wanted to criminalize abortion and opposed helping anyone but himself. He also loved pardoning white criminals and ignoring all othe races.
I know a blackstone company, who were a client of mine before they underwent a hostile takeover (blackstone fired everybody).
They claim to be ISO 27001 certified. They are not. They never removed me from their ISMS, and I can see it has not been touched in three years now.
Wait, it gets worse.
My root credentials still work, both for the app, and for AWS. Nobody has logged into AWS in years (hey, we built a reliable system).
I have unfettered access to highly sensitive (in some cases literally classified) commercial data for the likes of Apple, Siemens, Philips, BAE Systems, Raytheon, and more.
Wait, it gets worse.
They did something to the API endpoint. You can now bypass authentication entirely and anyone has access to this data.
There's nothing wrong with pitching stories this way, but for context, if you look at this researcher's archive, they're all basically "I found a vulnerability in some big company's thingy". The news hook here is literally just "I found a GraphQL bug". This is not Alex Schapiro's most interesting front-page story (by which I mean: they've posted some genuinely interesting stuff before).
reply