8 ms·
Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be
by bradrydzewski 9y ago
Responsible disclosure does not prevent negative publicity. It provides the vendor with a grace period during which they can fix the vulnerability. There can be plenty of negative publicity once the vulnerability is patched and publicly disclosed.
Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the process.
- camus2 9y agoAnd Full disclosure is about protecting users of a software, not letting the vendor off the hook. Here, the hack and the fix are so trivial the responsible thing to do is to publicly call out Apple for its lack of QA and warn users directly. It affects everybody who runs High Sierra. > it puts millions of Apple customers at risk in the process. Nah, it's Apple which put millions of customers at risk, not the person who disclosed the vulnerability. let's not shift away the blame from the guilty here. Apple one of the richest company in the world is obviously just cutting corners in QA here. This is unacceptable. it's seems some people here are more concerned about negative publicity than user security. This is a pattern that have been seen countless times in big tech corporations(such as Yahoo), not disclosing hacks that put their users and their data at risk. This is unacceptable for a company that claims to be all about their users.
- joshuaturner 9y agoI would argue that releasing this vulnerability as irresponsibly as he did is showing he cares more about negative publicity than user security. Yes, it's Apple's fault for poor QA that this was released, but this guy also put users at risk by telling the entire world about it without giving Apple a chance to fix it. You're right, it's about user security before publicity. So make sure users are safe first.
- jlgaddis 9y ago"as irresponsibly as he did" is how all vulnerabilities were announced, at one time. I miss those days, personally. Nowadays, you're "irresponsible" if you don't follow some vendor's own made up procedures.
- Angostura 9y agoYou can follow your own procedures - decide for yourself how long you think it is reasonable for the company to mitigate in private. But give the company some time.
- MatthewWilkes 9y agoWhy? You're not an employee, you're a concerned citizen. You havr no obligations to vendors whatsoever. Now, I think it's nice to do responsible disclosure, and I certainly don't envy the people whose week has been ruined, but the discoverer of this bug did nothing wrong.
- ptlu 9y agoIt is about the increased risk fellow users will have due to this style of disclosure. Who cares about the vendor, but they are best situated to resolve the issue quickly for everyone.
- SirZimzim 9y agoThe defense will stem primarily from users invested in the Apple ecosystem. If anything that is very concerning on its own.
- COMMENT___ 9y ago> Nah, it's Apple which put millions of customers at risk, not the person who disclosed the vulnerability. let's not shift away the blame from the guilty here. Disclosing 0day vulnerability via Twitter for the sake of self promotion is bad. Especially when you advertise yourself as a software developer.
- kristofferR 9y agoClosed disclosure does, to a large degree, prevent negative publicity. I don't think it is in dispute that this bug would receive vastly less media coverage if it were only revealed as a bug in outdated/patched versions of the OS. I don't want to see Apple hurt (I'm an Apple-guy myself, using Macs, iPhone, iPad and Apple Watch), I want to see them improve. I doubt they start will start caring about QA unless they're forced to. One absurdly serious and stupid password bug like this can be a honest mistake, but three (that we know of, that were full disclosures) in a few months is negligence that should be criminal if it isn't.
- ukblewis 9y agoI actually do think it is in dispute. This is a tweet after all. This guy could totally tweet about it in much the same way after Apple released a patch. The negative publicity would still exist because the bug would be equally stupid and disastrous, just fewer people would be harmed along the way.
- mark-r 9y agoIt wouldn't be as clear that the bug is widely reproducible after the patch is put out. And it certainly wouldn't gather as much attention.
- freedomben 9y agoExactly. Everyone I know on Mac immediately tried reproducing this bug the moment they heard about it. On those systems where it didn't reproduce, they immediately dismissed it as a false report.
- ksec 9y agoThat is assuming people patch their Mac ASAP. It will still be on high alert for most media if they have disclose it few days after the bug was fixed.
- deleted 9y ago[deleted]
- sydney6 9y agoNot the attitude of the people reporting the issue have put "millions of apple customers" at risk, but the company which allowed to let issues like this one slip through their Q&A process. IMO, this behaviour is part of the problem, the reason why tech companies take security only on a superfiscial level seriously. Don't kill the Messenger.
- bradrydzewski 9y agoI think this incorrectly interprets my comment. I am not defending apple or blaming the individual that disclosed the vulnerability on Twitter. I am simply pointing out that putting users at additional risk because you want to see Apple hurt may be misguided. We have responsible disclosures in place for a reason. EDIT: putting users at _additional_ risk
- philipwhiuk 9y agoThey were already at risk.
- mark-r 9y agoMaking an exploit widely known increases the risk dramatically.
- testvox 9y agoNo... I immediately set a root password, if this had not been posted I would be far more at risk.
- mark-r 9y agoMaybe you personally are at less risk, but the population as a whole is at greater risk.
- patcheudor 9y ago
- joe_the_user 9y agoA bug like 'can log in with password "root"/""' just isn't going to get you a grace period no matter what security researchers might want. I mean, this bugs has been reported already - by every cheesy hacking movie ever, by every beginners book on social engineering and so-forth. Heck, it was "reported" by Richard Feynman talking about cracking safes during the Manhattan.
- r3bl 9y agoGrub's "backspace 28 times to a rescue shell" was also a stupid one, but it first got fixed, and then made it to the news.
- copperx 9y agoThis reminds me of jwz's XScreenSaver rant. https://www.jwz.org/xscreensaver/toolkits.html https://www.jwz.org/xscreensaver/toolkits.html
- Sohcahtoa82 9y agoFYI...that's currently forwarding to a very NSFW image.
- djsumdog 9y agoHuh. It's only doing that if you go there from HackerNews. He must have a rule that checks the http-referrer O_o
- spiznnx 9y agoIt only forwards if the referrer is HN.
- ybloviator 9y agoYes it is. But being a brilliant brogrammer, I figured out how to view the link.
- deleted 9y ago[deleted]
- beedogs 9y agoThere is nothing irresponsible about disclosing huge vulnerabilities in software by any means necessary. Edit: as usual, downvotes but no response. I miss when this place was decent.
- rched 9y agoWhy not? The end goal is protecting users. If disclosing a vulnerability before a company has a chance to fix it puts more users at risk than waiting how is that not irresponsible?
- beedogs 9y agoConsidering the vulnerability was supposedly brought to Apple's attention a month earlier via the "proper" channels, and considering Apple's history of repeatedly ignoring and dismissing said disclosures, I'd say this was the only correct action to take.
- deathanatos 9y ago> as usual, downvotes but no response The very comment you are replying do lists a reason why disclosing huge vulnerabilities without providing upstream time to patch is irresponsible: "because it puts millions of Apple customers at risk in the process." Your comment doesn't refute the reasoning the comment you are replying to provides, and it also doesn't tell us anything about why you think "There is nothing irresponsible about disclosing huge vulnerabilities in software by any means necessary." You state your position, but offer no rationale, no reason for it; why should I accept your position as the correct or ethical thing to do?
- AlexandrB 9y ago> Encouraging irresponsible disclosure because one wants to see Apple hurt is a reckless and selfish attitude because it puts millions of Apple customers at risk in the process. Apple put millions of their customers at risk by skimping on QA. As an Apple user I'm OK with this getting out if it motivates Apple to improve their approach in the future.
- Animats 9y agoThis is such a lame vulnerability that it's probably already known to competent attackers. It's not a bug; it's a bad design decision. How to initialize the root password on a new machine is a hard problem in a consumer environment. Some people will set it, lose it, and then want support to fix it. One would expect some clever Apple solution, such as initializing the password to random letters and providing the buyer with that info on a scratch-off card. That way, the buyer can be sure no one has seen the password before they use the scratch-off card. Setting it to null? That means nobody thought about the problem.