3 ms·
First: everyone is already at risk for everything that P0 finds. The difference is no one if publicly talking about the flaws or the risk in the open. Second:
by billyhoffman 7y ago
First: everyone is already at risk for everything that P0 finds. The difference is no one if publicly talking about the flaws or the risk in the open.
Second: P0 never “immediately places people at risk” because they always follow responsible disclosure.
P0 has a well documented and frankly fairly conservative policy before anything is publicly disclosed. Do vendors want more time to fix things? Sure, they always will. Do P0 disclosures sometimes happen publicly before the vendor has things fixed? Yes, Occasionally. However, looking at the net, P0 has provided far more value than they detract with public disclosure of flaws
- mehrdadn 7y ago> First: everyone is already at risk for everything that P0 finds. The difference is no one if publicly talking about the flaws or the risk in the open. You don't see how the risk might increase when more people learn about the vulnerability? > Second: P0 never “immediately places people at risk” because they always follow responsible disclosure. What? They provided proof-of-concept exploits just one week after the patch was provided. That's apparently not "immediate" in the eyes of security researchers, but try asking the average user if that's enough time to expect them to update. > P0 has a well documented and frankly fairly conservative policy before anything is publicly disclosed. Yes, and it could be worse, but it's also not great and could also be better. > Do vendors want more time to fix things? Sure, they always will. That was never my argument. I never said they should get more time to fix things. > Do P0 disclosures sometimes happen publicly before the vendor has things fixed? Yes, Occasionally. Again, I was specifically NOT arguing about disclosing before the patch is provided. > However, looking at the net, P0 has provided far more value than they detract with public disclosure of flaws And I never singled out P0 or claimed otherwise. I'm disputing the entire practice by whomever is practicing it.
- jachee 7y agoiOS users tend to be relatively quick about upgrades. Plus, the publication of the announcement contributes to word-of-mouth dissemination of the existence of the vulnerability and prompts those who haven't updated yet to do so.
- deleted 7y ago[deleted]
- JakeTheAndroid 7y ago> You don't see how the risk might increase when more people learn about the vulnerability? Do you see the risk of having a vuln that is completely unknown still exploitable in your stack? > What? They provided proof-of-concept exploits just one week after the patch was provided. That's apparently not "immediate" in the eyes of security researchers, but try asking the average user if that's enough time to expect them to update. Why are critical issues not being patched within 48 hours? The disclosure of the issue can only mitigate so many things, and patch schedules by vendors is not one of them. If your vendor takes 3 months to patch the system, is that the requisite amount of time the researcher should be expected to wait before disclosure? That seems preposterous. > > Do vendors want more time to fix things? Sure, they always will. > That was never my argument. I never said they should get more time to fix things. So then that is your argument. What is a reasonable amount of time, and why is your arbitrary value not arbitrary? A day, a week, a month, a year; when can you ever be sure you've reached the critical threshold of patched systems using a rule of thumb?
- godelski 7y agoApple controls updates, not the carrier. So Apple updates happen pretty fast. I don't think we should wait for the carrier though. That's just months and honestly the carriers need pressure put on them or else they'll keep playing this lazy game and keep customers at risk. Because that's the truth. While a vulnerability exists users are still vulnerable. The difference of disclosure is that users know how they are vulnerable and they can hold carriers responsible.
- shkkmo 7y ago> That's apparently not "immediate" in the eyes of security researchers, but try asking the average user if that's enough time to expect them to update. "immediate" has a pretty clear meaning. You might argue that a week delay is not long enough, but it clearly isn't immediate. > try asking the average user if that's enough time to expect them to update. I would expect that yes, the average Apple user was updated within a week. You can also argue that if the rollout took too long, that is Apple's fault, not P0 Why is disclosure good? Companies: Disclosure in specific instances is often not popular with companies and they try to avoid it because of the bad PR is brings. However, companies benefit from the broad convention of disclosure because disclosures spread knowledge about how to write secure software and how to test for insecurities. Researchers: It seems pretty obvious that disclosure is good for security researchers. They get good PR and exposure, without a bug bounty program, that is all they get. (With a bug bounty program, disclosure is often restricted) Users: The risk profiles begin to change when a vulnerability is disclosed. After a patch, risks for unpatched users are always going to rise because the patch itself serves as a disclosure of sorts. After the disclosure, this risk does start to rise faster as the pool of people who can exploit the bug expands. On the flip side, disclosure is important because users need to know when they have been exposed to risk so they can take steps to mitigate that exposure. If a vulnerability allows remote code execution, installing a patch may not be enough if your system is already compromised. If a vulernability exposed communications you thought were secure, any credentials passed using that method need to be rotated. Finally, not all users' security is equally important. A grandma sending pictures of puppies to her grandchildren does not have the same security considerations as a human rights activist in China. You see this explicitly in embargoed disclosures where a limited set of organizations are informed in advance of the public disclosure. The length of time between patch and disclosure is thus a trade off between reducing security for high-security users and low-security users. The longer you wait, the more low-security users are patched, but the worse the risks become for the high-security users. You can't pick an optimum period on a case by case basis, because there are too many unknowns, so the best bet is to use a standard disclosure delay.