2 ms·
"In the case of yesterday's Node.JS release, which did not practice complete disclosure, and did put the fix in a larger patch, this did not prevent interested
by w0rd-driven 13y ago
"In the case of yesterday's Node.JS release, which did not practice complete disclosure, and did put the fix in a larger patch, this did not prevent interested individuals from finding out the attack, it took me about five minutes to do so, and any serious individual could have done it much faster."
I'd say you're spot on. I'm sure this wouldn't be the last "this is how you should really disclose" posts either. I prefer that approach to just lamenting about how terrible it was and fortunately there are many great examples to draw from.
- einhverfr 13y agoThere have been cases in LedgerSMB where we have had to do something like that. The SQL injection fixes in 1.2.0 were too numerous to backport without extensive beta testing, and the new permissions management system in 1.3.0 could not be backported for similar reasons. In both cases, the same workarounds were suggested. However, those really should be rare cases. It is worth noting that while we could not backport our anti-CRSF measures to 1.2, we did provide separate fixes to the most severe CRSF vectors (like those which could lead to account takeover).