4 ms·
Yeah, this is a stretch... I'm getting pretty tired of this kind of thing. It's pretty clear to me that the infosec industry (within appsec and netsec at least
by throwawaymath 8y ago
Yeah, this is a stretch...
I'm getting pretty tired of this kind of thing. It's pretty clear to me that the infosec industry (within appsec and netsec at least, not risk and compliance) is bifurcated into two distinct groups. The first group consists of people who have real technical expertise, find serious vulnerabilities and make concrete suggestions about legitimate issues.
The second group, and the one I see more and more often (especially in bug bounties), consists of people who find ridiculous "security" "risks" in all manner of things. They're not appsec or netsec people but they think they're identifying actual security issues. Sometimes they point out superfluous implementation issues but more often than not they're writing articles like this - nitpicking the design of a thing without clarifying their threat model and with only a vague grounding in the potential risk of compromise.
I mean did we really need a security PSA about the risk of email autoresponders? Come on.
- coding123 8y agoAt some point we just can't do more to thwart every possible threat. What are we going to be told to sneak out the back door of our house and walk 3 blocks to where we parked our car?
- jordz 8y agoAbsolutely couldn’t agree more.
- userbinator 8y agoI have heard the term "security vultures" being applied to the second group, and wish it was more common (the term, not the group...)
- CoreSet 8y agoI like "security fatalism" for the underlying behavior.
- sho 8y agoI've had a member of the second group, describing himself as a "certified white hat hacker", sign up for a small SAAS product I'm involved with, mess around a bit and then file a slew of "urgent vulnerability reports" of supposed security issues, all of them profoundly so-whattish in the context of a niche business SAAS. When I closed them all without further action, the chap then had the gall to demand payment - or at least a "certificate of appreciation" he could parlay into future business. Needless to say we declined. This lack of any concept of a threat model was precisely why his (considerable) effort was totally wasted and I can imagine similar "researchers" giving the industry as a whole a bad name.