4 ms·
Seems irresponsible to release this publicly.
by CheckHook 12y ago
Seems irresponsible to release this publicly.
- oofabz 12y agoThe security community has a long history of releasing flaws publicly. Take this recent libc gettimeofday() exploit, for example. I administer some servers and I am glad that I was alerted to the problem so I could address it. If that information had been hidden, then the problem would not have been fixed and eventually some black hat would exploit it. Publishing security flaws can cause problems in the short term but it's in everyone's best interests in the long term. It is vital that our infrastructure is protected against attacks and we can't afford to allow companies to sell and operate insecure industrial systems. Making this information public is the best way we have to get these problems fixed.
- nhaehnle 12y agoHow else do you get these people to change? We're not talking about a problem at a single company here. It's a wide spread issue of people apparently being either unaware or just not caring enough about security. A well-connected industry insider may be able to get things moving. But if industry insider exist who care enough, why hasn't this been fixed a long time ago? For an outsider, bringing the issue up in public is probably the most effective way to get this fixed. And it's not like they published a script to exploit this.
- irq-1 12y agoObama just doubled-down on the CFAA; our government and society doesn't want to know, and they don't care about 'the most effective way to get this fixed.'
- davidgerard 12y agoDecades of experience shows that revealing security problems leads to greater overall security than not doing so. Coordinated disclosure is to mitigate the effects of a particular case - but vendors routinely abuse it to sit on problems for months or even years (in their own interests), leading to a movement for full disclosure (in their customers' interests). Also, you seem to be assuming the bad guys don't know already. (This is why Microsoft's complaints about Google revealing their holes don't convince me: we already know Windows is peppered with holes that are unknown to the public but are literally commodities to criminals and national security organisations. Revealing all of them would increase our security and not decrease it even in the short term.)
- ZoFreX 12y agoSeems more irresponsible to build the systems this way in the first place.
- forgottenpass 12y agoSeems irresponsible to have unprotected IP-serial bridges online.