3 ms·
This speaks about Fortinet: "2018-06 - 2019-11: Multiple conference calls, discussing technical details, agreeing on disclosure time" Translation: half a year
by rdslw 7y ago
This speaks about Fortinet: "2018-06 - 2019-11: Multiple conference calls, discussing technical details, agreeing on disclosure time"
Translation: half a year to communicate:
- you send it unecrypted
- yes we do.
- GrayShade 7y agoThat's... a year and a half.
- gwd 7y agoGiven that the advisory advises you update rather than stop using them, hopefully a year and a half to actually implement some sort of actual encryption. And hopefully the reporters were paid for "discussing technical details", like, how to actually use an encryption library.
- retSava 7y agoWell, posting over HTTPS (with the worst certificates removed) instead of HTTP, perhaps with certificate pinning, isn't that hard and goes a long way.
- tialaramex 7y agoThis "XOR encryption" is vulnerable to an eavesdropper with almost no technical capability. Even just HTTPS with no checks whatsoever (think 1990s Perl scripts or Python Requests with all the checking explicitly switched off) is protected against eavesdroppers, so that would require an active attacker (or a large quantum computer) to defeat, far more sophisticated than this trivial nonsense.
- retSava 7y agoYeah exactly, that's my point - going from "oh shit" to "I feel fairly comfortable" in this case shouldn't take 1.5 years.
- tuczi 7y agoGood point. As far as I know, a long time to fix isn't an exception but rather a standard in such cases. That hursts even more :(
- danmg 7y agoThis is the problem with 'responsible disclosure.' Companies will just drag their feet indefinitely, like an undergrad who stalls and manages to talk the instructor into assigning them an incomplete instead of just failing them outright. Just flunk them and don't reward that behavior: full disclosure.