4 ms·
> If it's a concern, get a hold of the company and let them know. Easier said than done. It's hard enough to find the right people to talk to when people are s
by dthunt 15y ago
> If it's a concern, get a hold of the company and let them know.
Easier said than done. It's hard enough to find the right people to talk to when people are so paranoid about connecting devs with customers, and if by chance you wind up talking to a PM first, the first thing he does is engage legal, which means instead of fixing the problem and protecting their customers and data, you may now be threatened with lawsuits, have the incident reported to the FBI or someone for investigation (on the assumption that you are in fact trying to extort them or something).
In this world, I'm not sure you can 'win' at this situation at present. Until there are protections for white hats that are broadly recognized, I'm going to side with people like Egor, who find a big damn problem and don't use it for ill.
- sek 15y agoIn Germany we have the CCC, they provide legal advice for these cases and have a ton of experience. Do you have something similar in the states?
- dthunt 15y agoEFF has a network of people they can put people in touch with, even if for a variety of reasons they can't offer legal help in a particular instance. But that's not the point. While we can be grateful for the CCC and the EFF for existing and doing the community a great service, we can also believe that their extraordinary contributions should be unnecessary.
- JangoSteve 15y agoThat's a very good point about there not necessarily being a right answer. Though of all the companies in the world, Github is one of the easiest to get in touch with their developers.
- dthunt 15y agoAnd yet Egor made several attempts to illustrate the depth of a single problem, and nobody was able to understand that this was serious badness. Sometimes, it is actually necessary to pull down someone else's pants to expose a problem. I think the record here speaks for itself.
- JangoSteve 15y agoMaybe I missed something, but from looking through his posts, it seems that Egor felt the defaults in Rails were insecure (let's face it, they are), and then when he didn't get the immediate feedback from the rails team that he had hoped for, he decided to illustrate his point by hacking Github, which happens to be built on Rails. Nowhere did I read, on his own blog or within any of the rails issue tickets, that he actually tried reaching out to Github (i.e. contacting security@github.com) before exploiting the vulnerability. Maybe he did try to contact Github first, but I didn't see anything mentioning that in any of the linked posts.
- dthunt 15y agoThe immediate feedback was multiple issues closed as if they were not serious.
- PakG1 15y agoMaybe you do need to sometimes pull down someone else's pants to expose a problem. I think that's a moot point because nobody should really be able to disagree with that on pure logic. I think the important question is when someone feels they have no other choice, so they pull down the person's pants, should this be considered an immoral or criminal act? The guy can always say, "Look, I never intended to do any harm, I just wanted to get people's attention to fix this before someone who was intending to do harm came along." The problem is then how do you prove that they really were so benign? I think it'd be easy for a lot of blackhats to hide behind that if they ever got caught, or no? Even if there was complete immunity for people who immediately came out in the open and claimed responsibility for the sake of clearing the air, it'd still be easy for blackhats to hide their rationales in there, while they did something else more malicious (and then if that malicious thing was ever found, the blackhat can easily say, "Hey, I told you guys to fix it!! Now look what happened!! Wasn't me though!".