I work for a company building real estate adjacent software and have worked on connections to all the major property management systems and large (and small) proptech companies. I can tell you that at least 90% of them have some of the worst security practices you've ever seen. Many of the largest property management systems allow a third-party vendor to export your Social Security number and date of birth, and most property managers I've seen don't bat an eye at giving up as much information as their vendor requests (which they usually don't need).
Real estate is very much a closed of group of more traditional business and has not begun to understand their responsibility to keep this data safe.
Edit for more detail: To tack onto this, it's very much the case we're all familiar with where management doesn't care about something being built correctly, they just want it built. Add on top that the management usually has no technical background. Also add that very few engineers that are passionate about writing good software want to stick around at these companies. It's a real nightmare industry.
There are some companies that will give you faith, but they're the occasional large property manager that's been scared shitless about a security based lawsuit (fine by me) or a proptech that's "disrupting" the industry that will be acquired by one of the big dogs in 18 months and slowly eroded away.
Beam Living is just the property management company that runs buildings Blackstone owns in New York City. There are thousands of companies like this all over the country and if you poke hard at any of them you will find stuff like this.
There's nothing wrong with pitching stories this way, but for context, if you look at this researcher's archive, they're all basically "I found a vulnerability in some big company's thingy". The news hook here is literally just "I found a GraphQL bug". This is not Alex Schapiro's most interesting front-page story (by which I mean: they've posted some genuinely interesting stuff before).
Yeah I hear you but I think this community loves writeups like these -- I personally have learned a TON about how to be an effective security researcher by reading technical writeups others have posted here. Agreed this vuln wasn't a complicated one by any means but I feel like this is the forum for sharing this stuff
You mean the Blackstone namedrop? I had the same reaction. Beam is an internal division of Blackstone, for whatever that's worth, but I don't think there's a news hook about Blackstone here. This is, like, every property management company everywhere, whether indie or corporate.
If this is the case then IMO all the more reason to publicize it -- my SSN shouldn't be exposed just because I applied for a lease [ and we shouldn't just brush that off as something that is a given ]
I mean, that's true, and I'm not saying there's anything misleading about the post, just that this is true of basically all the companies that do this. All I'm saying is that there isn't a meaningful Blackstone hook here.
Beam is actually a little bit unique here. They have a spent a lot of money building a lot of custom software that most other property managers just buy off the shelf.
I work for a company building real estate adjacent software and have worked on connections to all the major property management systems and large (and small) proptech companies. I can tell you that at least 90% of them have some of the worst security practices you've ever seen. Many of the largest property management systems allow a third-party vendor to export your Social Security number and date of birth, and most property managers I've seen don't bat an eye at giving up as much information as their vendor requests (which they usually don't need).
Real estate is very much a closed of group of more traditional business and has not begun to understand their responsibility to keep this data safe.
Edit for more detail: To tack onto this, it's very much the case we're all familiar with where management doesn't care about something being built correctly, they just want it built. Add on top that the management usually has no technical background. Also add that very few engineers that are passionate about writing good software want to stick around at these companies. It's a real nightmare industry.
There are some companies that will give you faith, but they're the occasional large property manager that's been scared shitless about a security based lawsuit (fine by me) or a proptech that's "disrupting" the industry that will be acquired by one of the big dogs in 18 months and slowly eroded away.
Beam Living is just the property management company that runs buildings Blackstone owns in New York City. There are thousands of companies like this all over the country and if you poke hard at any of them you will find stuff like this.
There's nothing wrong with pitching stories this way, but for context, if you look at this researcher's archive, they're all basically "I found a vulnerability in some big company's thingy". The news hook here is literally just "I found a GraphQL bug". This is not Alex Schapiro's most interesting front-page story (by which I mean: they've posted some genuinely interesting stuff before).
Yeah I hear you but I think this community loves writeups like these -- I personally have learned a TON about how to be an effective security researcher by reading technical writeups others have posted here. Agreed this vuln wasn't a complicated one by any means but I feel like this is the forum for sharing this stuff
Yeah, you're totally fine.
Also, as far as I know, no residents were ever alerted that their data was exposed so this also is a bit of a public disclosure angle
There absolutely is everything wrong with implicating a company that has no knowledge of and no responsibility for the breach.
You mean the Blackstone namedrop? I had the same reaction. Beam is an internal division of Blackstone, for whatever that's worth, but I don't think there's a news hook about Blackstone here. This is, like, every property management company everywhere, whether indie or corporate.
If this is the case then IMO all the more reason to publicize it -- my SSN shouldn't be exposed just because I applied for a lease [ and we shouldn't just brush that off as something that is a given ]
I mean, that's true, and I'm not saying there's anything misleading about the post, just that this is true of basically all the companies that do this. All I'm saying is that there isn't a meaningful Blackstone hook here.
Beam is actually a little bit unique here. They have a spent a lot of money building a lot of custom software that most other property managers just buy off the shelf.
What a trashfire of a company. Where are the legal penalties for such reckless behavior?
Beam Living
https://www.beamliving.com/
yep
Great work, very detailed vuln report. Its what I'd want to see for triage and remediation.
Thanks!! Just trying to protect other's (and in this case, my own) data :)