3 ms·
Your argument that you'd have to be omniscient to make the optimal choice with absolute certainty is true of all human decision making at all times, and therefo
by gress 11y ago
Your argument that you'd have to be omniscient to make the optimal choice with absolute certainty is true of all human decision making at all times, and therefore doesn't change the argument at all.
You say 'given that we don't know who else had this exploit' there is value in rapidly securing a few people rather than letting them remain vulnerable.
The question here is has the public availability of the exploit secured more users from realistic attack than it has exposed?
The fact that the vulnerability wasn't publicly known before is evidence that it wasn't in widespread use. Not conclusive evidence, but evidence nonetheless. Not knowing who had the exploit before doesn't mean we have no information on which to base the decision, and certainly doesn't mean we should adopt a policy based on the idea that the exploit is currently in widespread use.
- scintill76 11y agoYou are right that my argument is sort of philosophical and not practical. > The question here is has the public availability of the exploit secured more users from realistic attack than it has exposed? It probably has exposed more. But, it could depend on whether some OS X servers were patched, or company-managed OS X workstations, or virus-scanner definitions updated, which could simultaneously protect many users. > certainly doesn't mean we should adopt a policy based on the idea that the exploit is currently in widespread use. In the current climate, I'm not so sure. Maybe not "widespread" use since, as you say, it doesn't seem to be publicly known. But, if it were only in narrow use and the discloser has determined this was the fastest way to warn people, do those narrow victims deserve security less than everyone else? Some of the discloser's statements make me wonder if he does know of other exploiters. You can question whether he knows enough or has the right to make that call, but if he disclosed responsibly, you'd be trusting Apple in the same way. Are they inherently more capable of making a good decision just because they're a corp? P.S. It's interesting that you seem to rely on "the community" to notice whether this was being exploited by malware, but are mad at somebody from "the community" reporting it without it having been exploited by malware. Of course I understand the reason this may not be the best way for it to be reported, but maybe we should be glad this was found and reported at all, for free, by someone in "the community." It almost seems entitled, to expect someone else to do you a favor for free, and for you to also dictate the terms.
- gress 11y agoWarning people isn't the issue. Apple is without question in a position to distribute a patch more rapidly and more widely than anyone else. It has nothing to do with trusting them because they are a 'corp'. There is nothing 'entitled' about the opinion that it's wrong to distribute information about malware publicly where it can be used by bad actors, without first giving vendors a chance to distribute a fix.
- scintill76 11y agoTechnically in this case, Apple was given advance notice: https://news.ycombinator.com/item?id=10070799 https://news.ycombinator.com/item?id=10070799 . I'm guessing we'd all agree it was not a reasonable amount of time to actually fix it... but then who gets to decide what that is? If I'm counting right, it took over a month for Apple to patch DYLD_PRINT_TO_FILE, which was disclosed in a similar way. IMO's it's naive to think nobody else knew about these relatively simple exploits, so I don't blame the reporter too badly for deciding they don't want to wait weeks for Apple to fix it, if they can fix it themselves in hours. It's useless for Apple to be "in a position to distribute a patch more rapidly and more widely than anyone else" if they don't actually distribute a patch rapidly. I guess we'll have to wait and see how rapid they are this time. I guess we'll have to agree to disagree. I'm at least glad to read around a bit that it's a controversial topic, so we're both in good company in our respective opinions.
- gress 11y agoYou keep saying things like 'who is to decide?'. If you really believed that, you would cease posting your opinions here. The point about people not wanting to wait for Apple is valid in that certain people can protect themselves ahead of apple distributing a fix. However it clearly doesn't change the calculus since the number of people who can protect themselves is miniscule compared to the number of people made vulnerable. Even if it takes a month, that is going to distribute the patch far faster than this. There is nothing controversial about this. It's a matter of statistics.