3 ms·
There is another reason why responsible disclosure would have been better (and less short-sighted): vendor might make an internal audit, find root cause and inv
by gdm85 7y ago
There is another reason why responsible disclosure would have been better (and less short-sighted): vendor might make an internal audit, find root cause and invalidate a bunch of certificates at once (think about similarly leaked certificates due to a bug in some deployment tool).
Now it's an open race with the bad guys, and surely a lot of them all at once; hardly an advantageous scenario for end users.
- JshWright 7y agoThat's an awfully big (and awfully optimistic) "might" in your first paragraph there...
- StavrosK 7y agoNot to mention that all the bad guys had to do to get the private key was unpack the firmware image, so they've probably noticed long ago.
- gdm85 7y agoIt's not optimistic, it's what a responsible vendor is supposed to do. By not following responsible disclosure the researcher has lifted the vendor from the possibility of organizing a proper response.
- gdm85 7y agoBy the way, I meant coordinated disclosure and I am not aware of Netgear not doing any at all, never.