3 ms·
Yeah, you'd have to actually do your fucking job. It's not up to one that did the fuck up to decide when people affected by the fuckup gets to know it happened
by adql 3y ago
Yeah, you'd have to actually do your fucking job.
It's not up to one that did the fuck up to decide when people affected by the fuckup gets to know it happened.
- Arnt 3y agoThat's a nice way to put it. It's nice because you omit the not-so-nice specifics and keep it nicely generic. You don't specify what the fucking job is, and you don't specify who gets to decide. I live in a country whose law explicitly protects the freedom of action. You can choose what you want to do and exceptions need good justification. The justification has to be a great deal better than "didn't do your fucking job" because the requirements on the fucking job are set out by contracts. Vendors and customers decide on the contracts between them.
- aaomidi 3y agoIf it’s actively exploited, more attention on it is good and not bad. That’s what the language requires. I don’t really care what contracts you have with people, if your software has an actively exploited bug in it, people should know.
- barelysapient 3y agoOh really? Lets say an issue meets the reporting criteria but a patch can only be deployed physically. And the exploit is a trival wireless attack on a pacemaker. By your reasoning, making sure everyone knows about the issue is a desirable goal? Come on. There has to be nuance. Things that might _literally_ kill people probably shouldn't be reported the in the same way as a bug in a 15-year-old ink-jet printer driver.
- aaomidi 3y ago> There has to be nuance. Things that might _literally_ kill people probably shouldn't be reported the in the same way as a bug in a 15-year-old ink-jet printer driver. The problem is, its actively being exploited. You're just keeping systems and people uninformed and unable to make mitigations.
- Arnt 3y agoThe only party that's sure to know the vulnerability and exploit is the exploiter. On the day the software vendor/operator learns that the vulnerability and/or exploit exists, the vendor may not know much more than "a vulnerability exists" (e.g. if the vendor discovers it by seeing data exfiltration). Who would you require, by law to inform people?