4 ms·
And Full disclosure is about protecting users of a software, not letting the vendor off the hook. Here, the hack and the fix are so trivial the responsible thin
by camus2 9y ago
And Full disclosure is about protecting users of a software, not letting the vendor off the hook. Here, the hack and the fix are so trivial the responsible thing to do is to publicly call out Apple for its lack of QA and warn users directly. It affects everybody who runs High Sierra.
> it puts millions of Apple customers at risk in the process.
Nah, it's Apple which put millions of customers at risk, not the person who disclosed the vulnerability. let's not shift away the blame from the guilty here.
Apple one of the richest company in the world is obviously just cutting corners in QA here. This is unacceptable.
it's seems some people here are more concerned about negative publicity than user security. This is a pattern that have been seen countless times in big tech corporations(such as Yahoo), not disclosing hacks that put their users and their data at risk. This is unacceptable for a company that claims to be all about their users.
- joshuaturner 9y agoI would argue that releasing this vulnerability as irresponsibly as he did is showing he cares more about negative publicity than user security. Yes, it's Apple's fault for poor QA that this was released, but this guy also put users at risk by telling the entire world about it without giving Apple a chance to fix it. You're right, it's about user security before publicity. So make sure users are safe first.
- jlgaddis 9y ago"as irresponsibly as he did" is how all vulnerabilities were announced, at one time. I miss those days, personally. Nowadays, you're "irresponsible" if you don't follow some vendor's own made up procedures.
- Angostura 9y agoYou can follow your own procedures - decide for yourself how long you think it is reasonable for the company to mitigate in private. But give the company some time.
- MatthewWilkes 9y agoWhy? You're not an employee, you're a concerned citizen. You havr no obligations to vendors whatsoever. Now, I think it's nice to do responsible disclosure, and I certainly don't envy the people whose week has been ruined, but the discoverer of this bug did nothing wrong.
- ptlu 9y agoIt is about the increased risk fellow users will have due to this style of disclosure. Who cares about the vendor, but they are best situated to resolve the issue quickly for everyone.
- SirZimzim 9y agoThe defense will stem primarily from users invested in the Apple ecosystem. If anything that is very concerning on its own.
- COMMENT___ 9y ago> Nah, it's Apple which put millions of customers at risk, not the person who disclosed the vulnerability. let's not shift away the blame from the guilty here. Disclosing 0day vulnerability via Twitter for the sake of self promotion is bad. Especially when you advertise yourself as a software developer.