4 ms·
This is why zero-days should be made public a week after reporting them to the company...without ANY fear of prosecution. Trust me, after the first 50 cases -
by TheButlerian 6y ago
This is why zero-days should be made public a week after reporting them to the company...without ANY fear of prosecution.
Trust me, after the first 50 cases - the companies will have a dedicated team working on such exploits.
Wow, they made this public and MS still didn't handle it...I guess it should be more widely advertised then.
- elmo2you 6y agoI fear that because of the asymmetric power/financial balance between the parties involved, such a choice could easily lead to a kind of war, in which the companies will have the upper hand. They will have may more means/resources at their disposal and when it gets ugly (out of the public eye) things could get nasty. Please, don't get me wrong. On itself I think this whole responsible disclosure culture is bullshit. It wouldn't be if more companies actually treated it more sincerely. But I have seen too many companies abuse responsible disclosure, or simply hide behind bug hunting programs to limit/squash exposure (too many times even without fixing anything), and then burn anyone who doesn't want to play by rules they themselves set. The problem is, there are far more things than just legal prosecution when this would turn into a clash between companies and security researchers. However, maybe a union or anonymous organization could level that playing field. Problem with that is that many security researchers also want recognition, at the same time as feeling safe (.. something about cake).
- TheButlerian 6y agoThey companies will still be under legal prosecution if they do something against the people that publish the leaks.
- gruez 6y agoJust publish it anonymously? Make a site called exploithub and host it as a hidden service. I'm sure most cybersecurity professionals wouldn't have problems accessing it.
- macintux 6y agoIf you’ve already disclosed it to the vendor, a leak of the information shortly thereafter would likely not be so anonymous.
- gruez 6y agoIf you're disclosing it to the vendor, then you're probably cooperating with them and are going to give them 90 days to fix it. If they don't fix it within that time, anonymously publish it a month or two after. That gives a total time of around 4-6 months between you discovering it and the "anonymous researcher" on exploithub "independently" discovering it.
- __s 6y agoNot sure why you're picking a week, that's hardly enough to escalate it to the right team. You're going to have publically announced zero days. Even if companies hopped to you'd get rushed deployments. There needs to be time to schedule the update etc, see also how long it takes for things to spread across Linux distros Besides, your point stands with Google's Project Zero preexisting 90 day period. & yet they get flak too about putting out this information (not that I agree with that flak)