Live data from Hacker News

Viewing profile — MZMegaZone

MZMegaZone

HN member
Joined
Wed, Jun 07, 2023, 12:53 AM UTC
HN karma
184
Public activity
20 items

About MZMegaZone

[ my public key: https://keybase.io/megazone; my proof: https://keybase.io/megazone/sigs/lw1wpDdIzWI0YvJ47RzBt4CDxSnkWrLSycmIOutcUsc ]

Recent public activity

  1. comment
    Comment #39393963

    We got around 150 submissions for 30ish panel slots over three days, so we're good there. Schedule should be out soon. The CVE program has grown and changed a lot the past few year…

  2. comment
    Comment #39393898

    Oh, I'll cash their check. I'll tell them, in professional terms, why they should change their policy, but I'll still cash the check.

  3. comment
    Comment #39391459

    License and passport have no first name and MegaZone for a last name. My SSN Card has 'Mr MegaZone' - when I changed it, back in 2000, the SSA said their computers just could not h…

  4. comment
    Comment #39390157

    Short answer: Badly. Long answer: Most DBs key on lastname, so MegaZone is my last name, officially, and I have no first name. Then I leave the first name blank if it'll let me, bu…

  5. comment
    Comment #39389866

    That's just a braindead policy. Really, really dumb. Not at all good security, just checking boxes.

  6. comment
    Comment #39389823

    https://www.nginx.com/blog/quic-http3-support-openssl-nginx/ I know there are other mentions - it's been in the commercial product since R30, hence the CVE.

  7. comment
    Comment #39389606

    OK - I need to make very clear that I'm speaking for myself and NOT F5, OK? OK. Ask yourself why this matters? What is the big deal about having a CVE assigned? A CVE is just a uni…

  8. comment
    Comment #39388857

    Exactly - this very question came up. And pretty much everyone looked at me as I'm the one who sits on every CVE.org working group (BTW, the CVE rules are currently being revised a…

  9. comment
    Comment #39388709

    That's a whole different discussion - which isn't as dramatic as it is being made out to be. Other hats I wear (outside of my day job) include being on every (literally, every) CVE…

  10. comment
    Comment #39378902

    Those were great times. I learned a hell of a lot working at Livingston, because we had to. We were basically a startup selling to ISPs right as the Internet exploded and we grew l…

  11. comment
    Comment #39378554

    You're all also missing the fact that the vuln is also in the NGINX+ commercial product, not just OSS. Which has a different release model. Being the same code it'd be darn strange…

  12. comment
    Comment #39378538

    That's actually supported by the CVE program rules. Have at it if you find examples with security vulns.

  13. comment
    Comment #39378523

    We know a number of customers/users have the code in production, experimental or not. And that was part of decision process. The security advisories we published do state the featu…

  14. comment
    Comment #39378468

    Internally at F5 (where I work as a Principal Security Engineer in the F5 SIRT and was one of the people responsible for making the call on assigning the CVEs).

  15. comment
    Comment #39374881

    Yes, those are the two CVEs I was referring to. All I know is he objected to our decision to assign CVEs, was not happy that we did, and the timing does not appear coincidental.

  16. comment
    Comment #39374799

    Yeah, I've been with F5 since 2010 - gotta love those old PortMasters though, Livingston was good times, until Lucent took over. I was there 95-98. I don't know what else there is …

  17. comment
    Comment #39374599

    No, a MegaZone. Haven't you heard, we come in six packs now. ;-) Yeah, very, very likely one and the same. Since 1989.

  18. comment
    Comment #39374503

    I think you'd have to ask Maxim. My take is he felt experimental features should not get CVEs, which isn't how the program works. But that's just my take - I'm the primary represen…

  19. comment
    Comment #39374327

    Yep. Maxim did not want CVEs assigned.

  20. comment
    Comment #39374312

    We (F5) published two CVEs today against NGINX+ & NGINX OSS. Maxim was against us assigning CVEs to these issues. F5 is a CNA and follows CVE program rules and guidelines, and we w…