4 ms·
How is it misleading exactly? > Vulnerability disclosed to IMETS@tencent.com. > Vulnerability disclosed again via Tencent Security Response Centre (TSRC) web
by capableweb 3y ago
How is it misleading exactly?
> Vulnerability disclosed to IMETS@tencent.com.
> Vulnerability disclosed again via Tencent Security Response Centre (TSRC) web portal.
> Tencent: “Thank you for your interest in Tencent security. There is no low or low security risk for this issue. We look forward to your next more exciting report.”
> Tencent: “Sorry, my previous reply was wrong, we are dealing with this vulnerability, please do not make it public, thank you very much for your report.”
> Tencent’s initial rejection of our disclosure and subsequent about-face served as inspiration for the title of this report.
It's a direct quote from a Tencent reply.
- paxys 3y agoJust because it is a direct quote doesn't mean it can't be misleading when shared without all the necessary context. Tencent asked for it to not be made public during the period while they were actively fixing it and well within any standard vulnerability disclosure deadline.
- JohnFen 3y agoI agree. I don't see anything here that seems out of line.
- 015a 3y agoBecause they said it essentially as soon as the vulnerability is reported. That's an entirely reasonable thing to ask for; don't make this public, we're working on it. And its a totally normal allowance from security researchers. The title induces readers into thinking that they said this in some other context. Example 1: They aren't working toward fixing it, don't release this, lets just keep it hush hush. This isn't what happened. Example 2: They did fix it, but they didn't want the researcher to publish details of the problem after they fixed it. This also isn't what happened. Assuming I understand the context correctly; its absolutely an inflammatory title that has no place in security disclosure articles like this.
- netsharc 3y agoYeah, kinda disappointing that the CitizenLab folks are exploiting the (I presume) non-mastery of subtle English of the developers to create a "clickbait" title. If they were English speakers they would've written something along the lines of "We thank you that you respected the vulnerability disclosure policy and notified us. We expect you'll continue respecting the policy and not publish this vulnerability before we resolve the issue and after a period of time where the updated software has been uploaded."
- drekipus 3y agoI agree that it's a miscommunication but batting for citizenlab here, it's just an all-round misunderstanding of culture and language. Chinese culture had a very strong "save face" mentality, especially big companies that have much government involvement. So they aren't going to admit fault or indicate that they have to do something. The correct response to tencent's initial response, was to say that you are looking for status update and will disclose vulnerability by X time. Please let us know when the issue has been fixed.
- ysavir 3y agoWhen I read the title, my impression wasn't that it regarded keeping a vulnerability private until fixed, but that there was some functionality that tencent didn't want people to know about.