5 ms·
A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, th
by CiPHPerCoder 9y ago
A lot of people in IT (a surprisingly high portion of programmers, even) don't understand the value of full disclosure in security research. For some reason, they decided to export their usual arguments to decry Tavis's tweet:
https://twitter.com/taviso/status/860679110728622080 https://twitter.com/taviso/status/860679110728622080
The responses to his tweet calling him irresponsible are consistent with the tone of this remark. "This can help the bad guys". Nevermind the fact that there's no details in the tweet relating to the actual vulnerability or exploit.
To be clear: I don't know what relationship (if any) Graham Cluley has to the people being jerks to Tavis, and it's possible that this quote was taken out of context. However, given the backlash Tavis's tweet summoned from some Twitter users with inflexible opinions about disclosure ethics, and this alien remark in the article, I'd hedge on the two being related.
- SA500 9y agoGraham's a longtime critic of Tavis. Think he used to work for an AV provider. Here's the history anyway https://www.google.co.uk/search?q=Graham+Cluley&oq=Graham+Cluley&aqs=chrome..69i57&sourceid=chrome&ie=UTF-8#q=Graham+Cluley+Tavis+Ormandy https://www.google.co.uk/search?q=Graham+Cluley&oq=Graham+Cl...
- snakeanus 9y agoIt seems that he is the Sophos guy.
- mikhailt 9y agoThere are many sides to this and you're generalizing it to people not understanding the full value of security disclosure is misleading. I can assure you a lot of those people fully understand the value of security disclosures and they are for it. What many people have the problem with, is with Tavis' tone and his approach to announcing his findings. No reasonable security researchers find a bug, announce it first to Twitter or other mass public postings and then inform affected vendor(s) with the disclosures. That's not it should be done and it is not a responsible discourse policy, this is what people have problems with Tavis. Tavis is doing amazing work, work that we need but he has to be careful with how he announce his findings to the public.
- mikeash 9y agoWhat's wrong with an announcement like this? With literally no details, it's not helping bad guys (or, for that matter, good guys). I can see an argument that it's unprofessional to call out a company when you need them on your side. But is anyone making that argument? All the negative replies I saw to that tweet, for example, are along the lines of "omg you ruined my weekend why couldn't you wait until Monday?"
- mikhailt 9y agoNot this tweet specifically, look at the tweets he did in the past where he did point out the names such as LastPass and 1Password. It caused some folks to contact these vendors for more information where they don't have any yet at the time of the tweets. Like this one: https://mobile.twitter.com/taviso/status/760231214812844032 https://mobile.twitter.com/taviso/status/760231214812844032 Or https://mobile.twitter.com/taviso/status/845717082717114368 https://mobile.twitter.com/taviso/status/845717082717114368
- mikeash 9y agoHow is that different from pointing out a name like Microsoft? Either way, it might be uncouth, but I don't see the connection to responsible disclosure.
- mikhailt 9y agoIt's not me that is having a problem with this, I'm just pointing out why some people are having problems with Tavis in general. You don't think it is reasonable to at least tell a vendor there is a security problem first before telling the rest of the world? Maybe responsible disclosure is the wrong name for this, I like the coordinated disclosure idea better. Maybe I am using the wrong terms but I cannot edit my post anymore.
- mikeash 9y agoI think it's reasonable to tell the vendor first. I don't think it's reasonable to freak out about a general, detail-free announcement, and especially not with "omg there goes my weekend" and "you're helping the bad guys" nonsense. The mere announcement of the existence of a bug, with little enough detail that it won't help anyone find it (i.e. "RCE in Windows" is useless), does no practical harm. It might be a bit rude. It's the announcement of details that help people find the bug that hurts. If the original announcement was "RCE in Windows due to type error in malware protection JavaScript interpreter" then that would potentially help bad guys put together an exploit before good guys can release a patch. Stuff like responsible disclosure (coordinated disclosure would be a fine term too) is about the second one, only, as far as I understand it. It's about mitigating the practical effects of the vulnerability as much as possible, not about protecting the reputation of the company or avoiding rudeness.
- Angostura 9y agoI suppose the issue that I have with that Tweet is - exactly what is its purpose - I don't think it poses a risk, but the tone - excited?, self-important? doesn't sit well with the idea of a professional security bod soberly reporting a serious problem. I just think the tone rubbed people up the wrong way.
- aeleos 9y agoIf people don't know that a vulnerability exists (For example: the Intel Active Management Technology) it can be very easy for the company to just ignore it. (Especially if it is one that reflects badly on the company) However, if people know that a vulnerability exists, it puts the ball in the companies court to do something about it. However, that is just my personal opinion about the reason for Travis' tweets (which happen every time a large vulnerability is discovered), and I have no security background. I trust that people like Travis, who have done a lot of work to improve security, to know how to minimize the damage from the vulnerabilities.
- sangnoir 9y ago> I don't think it poses a risk, but the tone - excited?, self-important? doesn't sit well with the idea of a professional security bod soberly reporting a serious problem. What a surprise! Self-importance in an security industry that relies on reputation for consulting gigs?[1] You might have missed the ominous, grandiose vulnerability names, fancy logos and the PR-blitz now associated with any vulnerability worth a damn. I'm an outsider, but even I know NetSec twittersphere is that last place to expect 'sober' communication. 1. I don't agree with your assessment that there was self-service in Tavis' tweet. To my knowledge Google Zero doesn't consult for anyone, he was probably excited and very surprised by what he saw and he needed to get it off his chest.
- benmmurphy 9y agoi think tavis's tweet is completely fine. even if someone managed to work out the general location of the code from the tweet [tavis has been looking at AV and Natalie does research on scripting VMs -- a big stretch] then its still an enormous effort to find the problem code and further effort to create an exploit. i doubt it would be possible to do by the time microsoft patched it. but as a researcher you to have to be careful with details sometimes. i've been able to reverse engineer java exploits from security explorations full disclosure posts in the past but these contained significantly more details than tavis's tweet.