3 ms·
Who is "the public" here? Why should package maintainers be hearing about this any sooner than me? I may not help maintain a popular Linux distribution, but I m
by aculver 13y ago
Who is "the public" here? Why should package maintainers be hearing about this any sooner than me? I may not help maintain a popular Linux distribution, but I may very well run a service that my customers' bodily safety depends on the encryption of the SSL connection. (Hypothetical.) After disclosure, my only option is not to wait for a fix from my vendors and service providers, but to shut down my service (and lock out my customers) until a fix is available from them (or my own efforts) hours later. Otherwise, the bad actors who would benefit from seeing their SSL traffic would have hours to do so, and for some of us that can cost lives.
This marketing page was effective communication not just to the public, but the hundreds of thousands of technical people that needed to understand that this disclosure was different, they needed to take action, which in this world of plentiful managed hosting, is really not typical.
- teacup50 13y ago> Why should package maintainers be hearing about this any sooner than me? Because they vend updates to the vast majority of users. It's about maximizing people's ability to get the fix quickly upon public disclosure. > ... they needed to take action, which in this world of plentiful managed hosting, is really not typical. What action do you think you need to take? Revoking certificates? Almost nothing checks OCSP or CRLs anyway, there's hardly a rush. All this marketing has done is sent ill-informed people scurrying.
- eropple 13y ago> What action do you think you need to take? Waiting until Debian gets its shit in order is not sufficient for a number of friends of mine who work at places that take security very seriously. They disabled access as soon as it became public knowledge.
- forgottenpass 13y agoI may very well run a service that my customers' bodily safety depends on the encryption of the SSL connection If that is the case, your FMEA needs to include undisclosed vulnerabilities in your communication channel's encryption, and the mitigation can't be telling the internet your particular opinions on responsible disclosure.
- aculver 13y agoWhew. Good thing I don't run such a service. :-) (Edited my comment to better emphasize that it was hypothetical.)
- forgottenpass 13y agoI knew it was hypothetical, I was just building off my experience with this as a reality and not a thought experiment. I think that your hypothetical is useless to this conversation. The seriousness of death is a good argument tool, but using it in the context of responsible disclosure is theatrics. Arguing for people with privileged access to the exploit to behave the way you want when disclosing it, is a lot like arguing that people with privileged access to the exploit behave the way you want when exploiting it (ie: don't exploit). When human safety relies on an encrypted channel, you have no option but to assume people aren't going to act the way you want. If you could get people to act the way you want, you wouldn't need to use an encrypted channel in the first place.
- aculver 13y agoYup. It's a great point. I do frequently mention the safety aspect in conversations about secure channels because I know that was how the importance of the work was pitched to me when I worked with a VPN provider in the past. (As a developer, but not in a role where I would have anything to do with the FMEA you mentioned. I had to look that acronym up.) I think it's a good point for people to keep in mind.