4 ms·
This is not an uncommon practice at all. There are other projects that provide early notifications to large vendors. Part of the point of that early notice is
by breser 14y ago
This is not an uncommon practice at all. There are other projects that provide early notifications to large vendors. Part of the point of that early notice is so binary packages can be available. Packages can't get built, tested and released alongside security announcements without someone getting early notification. Users are in a much better position if the binary packages are available when the announcement hits than if the announcement hits and the binaries are available a week later.
If the issue leaks out early or someone independently finds it they're just in that much better of a position to release the fix. Vendors will be closer to having packages ready.
Yes, it's probably not entirely fair. But there's no way to tell everyone without telling the bad guys too. The risk of telling select people to get the ball rolling is worth it if the entire ecosystem is ready when the announcement comes out.
Dealing with these issues is always going to be about managing the risk. You can't draw a line in the sand.
- tensor 14y agoI thought the point of the delay was so that people could not reverse engineer the patch through the source or binaries? I suppose with Heroku being a service it might be the case that people don't have access to the new patched binaries. If that's the case, then there is no issue.
- breser 14y agoI can't speak for the specifics of Postgresql or Heroku. But in my experience the expectation is that you're supposed to control access to the information. If you produce binaries you're not supposed to make them accessible prior to the embargo date. If you can upgrade without revealing the binaries I don't really see a problem with doing so.
- vetrom 14y agoResponsible versus full disclosure is a debate rooted in problems far older than HN. At least we get to see security issues in the light these days!
- breser 14y agoI'm not sure this is a case of responsible vs full disclosure. Obviously, we don't have full disclosure of the issue yet. However, that doesn't mean we won't have it on the 4th when Postgresql said they would be releasing their fix. To some degree I don't think "full disclosure" and "responsible disclosure" are very useful terms since they have so many different interpretations. But looking at this particular practice, I'm not sure there's been much debate in the open source world about this practice of pre-notification to vendors/large installations. In my personal opinion I think it's absolutely necessary. Most open source users depend on binary packages provided by someone else. Unlike a closed source model when everything happens within a single company. Even then I'd be surprised if some of this doesn't happen with large customers with closed source software. So in practice I don't think it's anything that doesn't happen with just about all heavily used pieces of software. It's just that this case happened to be more obvious this time. Largely because Postgresql closed their public repository in order to package the fix and announced that they were doing so.