3 ms·
We can safely assume that black hats have moles on these lists.
by masterleep 9y ago
We can safely assume that black hats have moles on these lists.
- throwaway2048 9y agoyeah the idea you can keep something like this away from malicious parties across dozens of huge companies is a ridiculous farce.
- inlined 9y agoI've worked to mitigate other vulnerabilities within Google. at least with the vulnerability I helped on, I'm surprised at how good the information containment was. Based on my area of work and job title, I was notified of the software that was vulnerable and to contact them with further info if we used it. I wasn't allowed to talk to others without explicit consent, so I talked to my central contact to find the right PoC in my neighbor teams to know who I was allowed to pull into a room for any joint strategies. To everyone else, I simply said "sorry. On call is busy this week. I'm working on mitigating an undisclosed vulnerability." No questions asked. To this day I'm still not 100% sure the vulnerability is public so none of my peers know anything more than the time window in which I was distracted.
- wasx 9y agoI don't know why this was downvoted, it's a very reasonable assumption given the scale and spread of people who knew. Sure there's no evidence of any actual attacks exploiting this vulnerability, but that doesn't mean we can discount the chance that it was known to malicious parties before the wider public.
- IncRnd 9y agoUpvoted, because you are 100% correct, and I need to counteract the downvotes that you for some reason received. Edit: ... which is why I now received downvotes...