3 ms·
The author is a developer and professional security researcher. He responds to the security disclosure issue on the github issue page: > @ewindisch: > I al
by 23david 12y ago
The author is a developer and professional security researcher. He responds to the security disclosure issue on the github issue page:
> @ewindisch:
> I also remind everyone that if they feel there may be possible attacks
> against the current format, not to publicly discuss this on GitHub.
> If you do feel this way, I'll happily entertain a private discussion.
> While I generally prefer and encourage transparency in open source
> projects, we should be careful to practice responsible disclosure.
Disclosing security vulnerabilities is a responsible thing to do.
As a security researcher, it is entirely my choice how/when/if I disclose
security issues. In this case, I'm not dropping any 0-days, just pointing out
fundamental flaws in the current system. Fixing these flaws should be an
open discussion, not a private one.
As far as "responsible disclosure" goes, it is only one vulnerability
disclosure approach (the alternative is not "irresponsible disclosure"),
and there is zero consensus about it.
Source: https://github.com/docker/docker/issues/9719#issuecomment-67983737 https://github.com/docker/docker/issues/9719#issuecomment-67...
Some good reading by Bruce Schneier re:full disclosure vs responsible disclosure: https://www.schneier.com/essays/archives/2007/01/schneier_full_disclo.html https://www.schneier.com/essays/archives/2007/01/schneier_fu...
If you want to really understand the security world, I definitely recommend
attending Defcon in Las Vegas at least once to meet our Cyber brethren... :-)
Companies with the resources who publicly state that they care about security
should be willing and excited to at least partially sponsor employees to go.
Definitely worth every penny.