6 ms·
Full disclosure if you're a good guy, no disclosure if you're bad. "Responsible" disclosure is anything but.
by DanAtC 2y ago
Full disclosure if you're a good guy, no disclosure if you're bad.
"Responsible" disclosure is anything but.
- WaitWaitWha 2y agoCan you elaborate on your note? Asking because I had multiple bad experiences with responsible disclosure, yet I do not believe full (public presumably) disclosure is the right initial path.
- DanAtC 2y ago"Responsible" disclosure at best results in an embargo where "trusted" parties get to sit on it while the general public remains at risk. Worst case you get the cops knocking at your door. (Full disclosure should be done anonymously to prevent the latter from happening anyway)
- afavour 2y agoBut full disclosure places the general public at greater risk than responsible disclosure.
- michaelt 2y agoLet's say hypothetically someone found this hacked website, sent an e-mail to the site owners' security reporting contact, and after a year they hadn't taken any action. Some would say a "responsible" disclosure which allows the danger to continue unabated for a year is a greater danger than a public disclosure, which would lead to the danger being fixed.
- afavour 2y agoThat is one hypothetical scenario, yes. Another hypothetical scenario is that as a result of responsible disclosure the site owners patch the hole and ensure customer data isn't publicly accessible before the vulnerability is public knowledge. Seems reckless to me to not even _try_ responsible disclosure. You don't have to wait a year. But at least give a chance for the problem to be solved before you make it common knowledge.
- michaelt 2y agoDid I say hypothetically? Sorry, I meant to say exactly as happened [1] :) [1] https://news.ycombinator.com/item?id=40169334 https://news.ycombinator.com/item?id=40169334
- afavour 2y agoRight, so that’s a dataset of 1. Are you suggesting responsible disclosure never works because of your one time experience?
- michaelt 2y agoOf course not. I agree that responsible disclosure works perhaps 10% of the time. It's the 90% of the time, when it doesn't work, that's the problem.
- lynx23 2y agoOnly in the very short term. In mid-to-long term it increases the incentive to actually roll out a fix sooner then later.
- busterarm 2y agoOr you can possibly decide to shut down whatever service is vulnerable.
- busterarm 2y agoResponsible disclosure creates a ton of perverse incentives for all parties and ultimately leaves customers worse-off. Bug bounty programs and all of the drama and exploitative labor issues fall into this pit. Full disclosure might have short-term negatives for _companies_ involved but is best for customers/users as it allows them to evaluate and implement their own mitigations as early as possible. It's the only truly ethically consistent way to operate.
- cqqxo4zV46cp 2y agoThis really sounds like you’re back-solving from a pre-existing ideology of complete openness. A customer’s ability act early, e.g. mitigate, is quite clearly context-dependent. I can think of vendors I interface with as a customer that I’d prefer had vulnerabilities ‘responsibly disclosed’ to them. Nothing in technology is this simple. The absolute nature of your claims make it near impossible to actually take this seriously.