3 ms·
I wasn't being sarcastic. Adding a tagline, media friendly name or keywords is unprofessional. Simply, severity is then ranked by how popular the press or secu
by csmeu 12y ago
I wasn't being sarcastic.
Adding a tagline, media friendly name or keywords is unprofessional. Simply, severity is then ranked by how popular the press or security bloggers can market the word, not by the respective severity of the CVE. Its a popularity contest, nothing more.
As someone who deals with every damn sensationalist story at a financial company, having every fucking client phone up about every damn marketoid creation even if it doesn't affect our platform detracts from doing real work.
Let's play their trick:
Its the X Factor of security.
- Karunamon 12y ago"Professionalism" is overrated. And this appears to be a "drop everything and fix it" bug, so the "damn sensationalism" is warranted. If clients calling you about a vulnerability bothers you, get out of this line of work, please. People actually giving a shit about security holes is something we've been wanting for a long time. It beats the hell out of the alternative, something we've been dealing with since the 90s or so!
- csmeu 12y agoProfessionalism is thinking and understanding before you start firing a gun at your infrastructure, testing stuff and not shooting client SLAs. We do that bit between the CVE being announced and patching ahit, not when the press goes ape shit. So, that's overrated is it?
- __david__ 12y agoYes. When there's an exploit available now, you really don't have that luxury.
- jacques_chester 12y agoHis point is that severity is orthogonal to the coolness of vulnerability names. And that this will cause whacky priorities in future. Plus, 99% of the time, end users are not directly responsible for patching these issues. So why the focus on mass-media friendly marketing?
- Karunamon 12y agoIf the mass media is getting real life sysadmins to get bugged about security holes, how is that anything but a net positive?
- dsacco 12y agoThat's not the point. The mass media knows nothing about security. Here is what is happening when vulnerabilities get their own brand names, with logos and marketing: 1. Vulnerabilities are implicitly severe if they attract media attention (and only if they attract media attention). I've been featured in the press twice for vulnerabilities. Neither of them were as serious as the least serious, unpublicized vulnerability on this page: https://hackerone.com/internet https://hackerone.com/internet. 2. It implicitly encourages rating a vulnerability's severity by how much media attention it receives, not by an objective scale. It's causing a race to the bottom where coordinated disclosure now requires a PR firm, a presskit, a logo, and a brand name. For Heartbleed and Shellshock, sure, they're serious enough for all those hoops. For everything else, the race to the bottom will commoditize these things, making vulnerabilities without them ignored, and confusing vulnerabilities with them as severe. The final result is that it's just extra, meaningless noise tacked on to vulnerability disclosure that makes it more difficult to achieve, involves more parties and doesn't improve anything.