3 ms·
I wonder instead of notifying to select few parties with an embargo, if it would have been a better handled by releasing an encrypted sources with documentation
by rshm 12y ago
I wonder instead of notifying to select few parties with an embargo, if it would have been a better handled by releasing an encrypted sources with documentation containing the url to high availability server containing keys that serves only after pre-defined point in time. And documentation on integrity verification, accessment of the source changes and implications on other softwares using openssl.
- tptacek 12y agoHow would that not just be an overcomplicated way to do exactly what the reporters of this bug did anyways?
- ggggg5 12y agoI think the idea is that everyone would get the info at the exact same instant. It also allows everyone to be "at their computer" ready to implement the fix. It would mitigate the possibility of it leaking and getting exploited by someone.
- kelnos 12y agoThat's foolish, and doesn't take into account how software updates are actually rolled out in the real world. Many vendors will not just simply compile a new version of a library from upstream source and just throw it on their machines. They depend on a tested release from their distribution maintainer, or something along those lines. Also many vendors aren't prepared to do a simple upgrade: some may have customization they need to forward-port and test. Or perhaps they'd prefer to backport the fix to their older version. So basically, your "everyone gets info at once" means that blackhats can get the information and exploit it almost immediately, while the good guys scramble to -- much more slowly -- patch their systems.