3 ms·
Yahoo! released Axis (with this very dumb mistake) at 5pm PST, and by 9pm PST their public key is posted, with a "I report this but have yet to hear back" note.
by dws 14y ago
Yahoo! released Axis (with this very dumb mistake) at 5pm PST, and by 9pm PST their public key is posted, with a "I report this but have yet to hear back" note. How, exactly, is this responsible disclosure?
- zobzu 14y agoits a private key btw. wouldn't be any issue if it was a public key. its not responsible disclosure but then again, everyone could see the key after an hour. it's not like if it was a complex exploit. Its more like if you printed the password to your stuff on a document and told the world to grab a copy. ;-)
- jrockway 14y agoWhether or not the disclosure is responsible is irrelevant. What's irresponsible is uploading Yahoo's private signing key to the Internet. The author of this article is just warning others so they can uninstall the extension before someone uploads malware and Chrome auto-updates it.
- ktizo 14y agoIs a brand new thing with no userbase. Seems an extremely responsible time to disclose this. As I understand it, responsible disclosure is primarily there to protect the userbase of a piece of software, not the reputation of the producer of that software. And surely they can't be being stupid enough to be using this same signing key on established products, can they? On reflection, scrub that last thought.
- marshray 14y agoThe question isn't so much what other things Yahoo! might be using this signing key for, it's what other things bad guys might be able to sign with it.
- ktizo 14y agoThose two are sort of the same question however. If this is the only thing signed with this key, then the attack surface is only people running this thing.
- dmboyd 14y agoConsidering that in this case the "public end users" are the ones who are most at risk due to this vulnerability, I think its fair game that this be a public disclosure. i.e. people should delete this browser add on (and anything signable with the same key) as its been compromised.
- nikcub 14y agoI always, always, always go the route of contacting vendors - over the past 15 years I have reported hundreds of security and privacy vulnerabilities. This is the first time where I haven't reported to the vendor first before disclosing. The way this came about was a bit different, because it started with a tweet[1] where I pointed out that the file was there, and then it gradually developed into realizing that it is a pretty big deal. The discovery happen out in the open. If you look at my timeline and the replies and conversations you will see how it came about. With hindsight I could have handled it differently, but it just happen to come out in this way. I added an update to the end of the post addressing disclosure. The goal at the moment is to make users aware that there is potentially a big issue here. [1] https://twitter.com/nikcub/status/205489752684765185 https://twitter.com/nikcub/status/205489752684765185
- iuguy 14y agoIt's your bug, finders keepers. I always despair when I hear people talk about 'responsible disclosure', as it's a term so often used by vendors to keep finders quiet. By disclosing it at all you've highlighted the issue and Yahoo have rightly moved to fix it quickly. So I can sign a chrome extension with a valid cert for maybe a day, it's not the end of the world.
- lawnchair_larry 14y agoI too hate that term. Even Microsoft rejects it.
- tptacek 14y agoThere was zero (0) chance this wasn't going to get found 100 times independently whether or not you publicized it. Getting it out quick and loudly was absolutely the right move. You have nothing at all to apologize for.
- nikcub 14y agothanks. and you are right, at least two other people found the same thing, then searched twitter and found my post about it. one of them was @rasmus the creator of PHP (pretty funny timeline of him discovering and then finding on twitter).
- fffggg 14y agoResponsible disclosure exists in order to allow an obscure, previously undiscovered bug to be patched before others know about it. The idea is that no one else is likely to discover the issue while it is repaired. This is not an obscure bug. This is obvious -- very obvious. Many people will have discovered this already. Furthermore this is a pre-release product. There is nothing to be gained by not talking about it.
- sneak 14y agoYahoo were the ones doing the disclosure of the secret (the private key) when they uploaded it to the web. Please stop parroting "responsible disclosure" like a white knight, and engage your brain.
- DennisP 14y agoResponsible disclosure gives the vendor a chance to fix a flaw before everyone knows about it. In the case of a private key exposure, the only possible fix is to tell everyone to stop trusting that key. That's exactly what happened here.