3 ms·
Warning people isn't the issue. Apple is without question in a position to distribute a patch more rapidly and more widely than anyone else. It has nothing to
by gress 11y ago
Warning people isn't the issue. Apple is without question in a position to distribute a patch more rapidly and more widely than anyone else. It has nothing to do with trusting them because they are a 'corp'.
There is nothing 'entitled' about the opinion that it's wrong to distribute information about malware publicly where it can be used by bad actors, without first giving vendors a chance to distribute a fix.
- scintill76 11y agoTechnically in this case, Apple was given advance notice: https://news.ycombinator.com/item?id=10070799 https://news.ycombinator.com/item?id=10070799 . I'm guessing we'd all agree it was not a reasonable amount of time to actually fix it... but then who gets to decide what that is? If I'm counting right, it took over a month for Apple to patch DYLD_PRINT_TO_FILE, which was disclosed in a similar way. IMO's it's naive to think nobody else knew about these relatively simple exploits, so I don't blame the reporter too badly for deciding they don't want to wait weeks for Apple to fix it, if they can fix it themselves in hours. It's useless for Apple to be "in a position to distribute a patch more rapidly and more widely than anyone else" if they don't actually distribute a patch rapidly. I guess we'll have to wait and see how rapid they are this time. I guess we'll have to agree to disagree. I'm at least glad to read around a bit that it's a controversial topic, so we're both in good company in our respective opinions.
- gress 11y agoYou keep saying things like 'who is to decide?'. If you really believed that, you would cease posting your opinions here. The point about people not wanting to wait for Apple is valid in that certain people can protect themselves ahead of apple distributing a fix. However it clearly doesn't change the calculus since the number of people who can protect themselves is miniscule compared to the number of people made vulnerable. Even if it takes a month, that is going to distribute the patch far faster than this. There is nothing controversial about this. It's a matter of statistics.
- scintill76 11y agoWhen I say "who is to decide?", I mean, as we have discussed, there is no way to be absolutely sure of the best course given the unknowns, so that reasonable people can differ, and they will, based on differing ideologies on things like risk management, duties to the public, and personal agency. As for controversy, maybe I overstated that, but your flat counterstatement with no elaboration or support isn't going to change anyone's mind.
- gress 11y agoYou keep saying 'there is no way to be the absolutely sure' - but this is a truism that applies to all of human decision making. You are using it to make the situation seem less clear than it is rather than responding to a clearly articulated critique of your position. If you differ on any of these topics why not say what you believe?
- scintill76 11y agoIt does apply to all of human decision making, which is why we have different political parties, different schools of thought within a scientific field, different types of government etc. My point is that full disclosure vs. secrecy (and various points inbetween) is an instance of that type of dilemma, so that only a closed-minded person would insist their particular choice is the only position that is always right. As an example of how "responsible disclosure" can fail, read https://en.wikipedia.org/wiki/Shellshock_(software_bug) https://en.wikipedia.org/wiki/Shellshock_(software_bug) . It was embargoed until a patch was ready, but the patch itself invited exploitation attempts and further scrutiny which revealed additional vulnerabilities. It was quite a mess, but IMO the only "best practices"-based way to avoid it would have been to never have introduced the vulnerability in the first place. Elsewhere in this thread, I cited an instance of Apple taking three years to fix a vulnerability responsibly disclosed. Would you say it was better to let that vulnerability sit for three years than to disclose it immediately so that it would get fixed within a few months? Obviously none of this proves we should jump to instant full disclosure, I just mean the existing approaches all have issues, so there is room for personal opinion and judgment. I don't even feel strongly about second-guessing this particular instance, because I'm betting the discloser knows more than we do. (And if you don't trust him, refer to my previous comments -- why trust Apple, when they have a record of being fairly slow?) If I'm obfuscating by saying we can't know, you're making it deceptively simple by claiming you do know with broad statements like "the number of people who can protect themselves is miniscule compared to the number of people made vulnerable" (even though I've argued third parties can help secure unknowledgable users, if the issue is publicly disclosed before an Apple patch), "It's a matter of statistics", "the fact that the vulnerability wasn't publicly known" (how do you define "public" in a way that is both meaningful to your position and can be exhaustively searched to prove the "fact" that this wasn't known?).