4 ms·
Even at 16, you should be mature enough to know that this is classless. I hope for their sake they never start their own business and never fuck up, because tha
by pjhyett 16y ago
Even at 16, you should be mature enough to know that this is classless. I hope for their sake they never start their own business and never fuck up, because that'd be awfully sad if the next kids to come along decided to show them the same courtesy they've shown here.
- _phred 16y agoThis is just precious: @ElliotSpeck: > ...I'm available for consulting if you ever want to hire a security manager for @phpfog. :) As someone who takes security seriously, and manages shared hosting security for a living, I can't imagine what the PHPFog people are going through right now. Finding security holes in commercial systems and discreetly notifying the owners of the problem is one thing; broadcasting knowledge of the holes to the world without a reasonable wait is akin to criminal. I don't care if they actually exploited it, they just threw wide the door without a second thought.
- _Lemon_ 16y ago> Finding security holes in commercial systems and discreetly notifying the owners of the problem is one thing Last time this happened to me, I gave 6 months free on a dedicated server which was announced in an e-mail that went out to around a thousand users (the focus was explaining why feature x was disabled for the past few days). It was brought up in discussion that it was probably too much, but the alternative to me was terrifying considering the amount of tickets opened because of the preventative measures.
- _phred 16y agoYeah, in my experience, the best way to handle these things and keep goodwill is to own up to them and take responsibility for what happened; and explain to your customers what happened, what went wrong, how you fixed the problem and (hopefully) the entire class of problem, and what you've done to prevent the issue in the feature. A mature and honest response goes a long way.
- rbanffy 16y ago> broadcasting knowledge of the holes to the world without a reasonable wait is akin to criminal I wouldn't go as far as that. It's sure bad form, but disclosing a fact (maybe with the exception of immediate national security concerns) can't be considered a crime. This will cost the PHPfog folks some and they can - and should - pursue civil action against whoever causes damage to them.
- nbpoole 16y agoDisclosing a fact? No, that's not necessarily criminal. Publicly admitting to having committed a "computer crime"? That's a different story. I think the point _phred was trying to make is that publicly disclosing the issue like this puts all of the sites on PHPFog at risk.
- _phred 16y agoExactly; as I said, "disclosing a fact without a reasonable wait" which is fair and ethical in the security world. I'm all for full disclosure, but give the affected parties time to clean up the mess and get PR ready. After berating one of the "d00ds" involved on Twitter, it looks to me like he told his friend how to exploit the problem, and his friend (or his friend's friend) made the site and exploited the hole. If I show someone how to break into your house, and that person tells someone else "hey, nbpoole's house is open, let me show you," and your house gets broken into am I completely innocent of the crime? Security knowledge is the kind of knowledge that gets things broken into, so security people need necessarily be cautious with who they tell about security problems.
- yuhong 16y agoFYI, when I found about an open ASP.NET padding oracle at Subway.com, all I did was to run PadBuster to exploit it without damaging the servers in any other way. Eventually I reported it to feedback@subway.com, and only after a week of no response only then I finally posted it to reddit: http://www.reddit.com/r/netsec/comments/g9crj/open_aspnet_padding_oracle_at_subwaycom/ http://www.reddit.com/r/netsec/comments/g9crj/open_aspnet_pa...
- acangiano 16y agoAgreed. 5 days ago one of the hackers wrote on Twitter: "Wow, heroku for PHP. I thought of this once, sadly I wouldn't be able to get 1.2 mil in funding :(". Well, at least we didn't have to look too hard for a motive.
- twalker 16y agoIt is so petty I hope they get it sorted
- beaumartinez 16y agoDo you have a link for that tweet? Or a screen-capture?
- antonioc 16y agohttp://twitter.com/compwhizii/status/48172082667864065 http://twitter.com/compwhizii/status/48172082667864065 (I had to create a different account because I have no_procrast activated on my main account. It'd be awesome if no_procrast would be automatically disabled during the weekend.)
- darklajid 16y agoDuring which weekend? For my new place of work that would be on Friday & Saturday.. (Just a quick note that some features are harder than it seems at first)
- acangiano 16y agoI realize that it's harder than it looks. However, it would be trivial to allow people to choose the days they don't want the procrastination setting enabled (based on a standard timezone like PST.)
- eneveu 16y agoIn this case, I'd simply use LeechBlock or the Chrome equivalent, which has the features you want.
- rmccue 16y agoI'm a 17 year old developer, also from Queensland. The majority of us know what responsible disclosure is. Looks like someone missed the memo.
- EamonLeonard 16y agoWell said.