Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

91–100 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#91
post #87
post #8

Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…

> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…

I'd argue any kind of vulnerability announcement, even a zero-day exploit, is better than having the vulnerability be exploited under the radar by malicious actors. The existence of an exploit allows people affected by the vulnerability to know there's a threat, and to act accordingly.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#92

Earlier quoted context omitted.

I feel your pain at a deep and spiritual level. I have been in charge of at least half a dozen endpoint protection products over the years (deployment, configuration, management, etc.). Once a user experiences what you just described they are (rightfully) suspicious and sour towards endpoint protection. Questions i would ask in your example: 1) Was the core business tool excluded from the more intrusive protection mo…

Can I ask, since you're as a person who has administered endpoint protection products: how much legitimate stuff do they actually catch?

I work in offense and they can be a huge impediment. Significant work goes into bypassing or staying undetected from these products. While not all the detection occurs at runtime, they report a lot of data back from the endpoint so historical detection can happen.

However what I see is essentially their true positive and false negative rate, I would be interested to know what the false positive rate is.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#93
post #87
post #8

Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…

> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…

> Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat

I don't think it is upsetting at all.

"We found a vulnerability"

"There's no vulnerability"

"No, you misunderstand, here's how it works and how to exploit"

"Naah, no vulnerability"

"Ok, if there's no vulnerability as you claim, you don't mind us releasing our findings to the public, right?"

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#94
post #10

Earlier quoted context omitted.

It’s the snake oil industry. They don’t sell security, they sell CISO get out of jail cards in the form of client agents that constantly remind you of their divine presence by being on top of the CPU utilization sorted process list.

There is a LOT of snake oil in the industry, but endpoint protection IS useful. Not every person is a Hacker News reading tech enthusiast. People download and do dumb shit. That is not to say every device needs it and at a max “check every process/file activity” level, though.

Endpoint protection is theoretically useful.

In practice, most implementations cause more harm than good. Some of them even add vulnerabilities themselves.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#95
post #87
post #8

Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…

> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…

So what is an appropriate point in time to release information about an issue the vendor claims doesn't exist?

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#96
post #87

Earlier quoted context omitted.

> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…

> Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat I don't think it is upsetting at all. "We found a vulnerability" "There's no vulnerability" "No, you misunderstand, here's how it works and how to exploit" "Naah, no vulnerability" "Ok, if there's no vulnerability as you claim, you don't mind u…

The thing is, "releasing our findings to the public" puts the vendor's customers at risk, it's not just some imagined Just Punishment For The Guilty, innocents get hurt.

Imagine if you took a new job and they had a bunch of hardware sitting around from such a vendor. Would you be OK if someone published an exploit for your systems?

(In this case, the vulnerability seems minor, so it's sort of academic. But I'm not understanding the mindset of the people here who want to see this as a two party adversarial kind of relationship between Modzero and CrowdStrike. It's not!)

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#97
post #66
post #43

Earlier quoted context omitted.

Sounds more like these companies are using bounty programs to get researchers to sign NDAs so that they can control public perception of their products. Effectively paying people (and heaping ego gratification on top of that) to be silent about found vulnerabilities.

Well, sure. That's essentially the trade you're making with a bounty program: you pay people for finding stuff, and get to establish terms for disclosure. If you're not OK with those terms, you can almost always just ignore the bounty and publish directly.

Is there still a safe harbor if you go that route?

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#98
post #97
post #66

Earlier quoted context omitted.

Well, sure. That's essentially the trade you're making with a bounty program: you pay people for finding stuff, and get to establish terms for disclosure. If you're not OK with those terms, you can almost always just ignore the bounty and publish directly.

Is there still a safe harbor if you go that route?

You don't need "safe harbor" to test software you install on your own machine (which is what Crowdstrike is), and if you're testing someone else's server, you'd better have permission already.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#99
post #96

Earlier quoted context omitted.

> Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat I don't think it is upsetting at all. "We found a vulnerability" "There's no vulnerability" "No, you misunderstand, here's how it works and how to exploit" "Naah, no vulnerability" "Ok, if there's no vulnerability as you claim, you don't mind u…

The thing is, "releasing our findings to the public" puts the vendor's customers at risk, it's not just some imagined Just Punishment For The Guilty, innocents get hurt. Imagine if you took a new job and they had a bunch of hardware sitting around from such a vendor. Would you be OK if someone published an exploit for your systems? (In this case, the vulnerability seems minor, so it's sort of academic. But I'm not un…

You can't let vendors hide security problems by just not doing anything about them. People deserve to know if the product they rely on has vulnerabilities, because just because you aren't exploiting it doesn't mean nobody else will find it.

Modzero was even following a more conservative playbook here: not setting a deadline from the start, but only talking about release once the vendor indicated there was no issue (anymore).

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#100
post #88

Earlier quoted context omitted.

if they have a disclosure process, what purpose is served by the non-disclosure agreement? what with non-disclosure being literally the opposite of disclosure & everything

They pay you money, you disclose exclusively on their terms. That's the deal, and the purpose of the NDA. If you don't like the NDA terms, you don't engage with the bounty program, and you just publish on your own. There's no reasonable way to make a whole big thing out of this.

right, if you don't like the terms of the NDA, don't agree to it

that is precisely the choice made by the team in the article, because the NDA was bad, for the reasons you described

so it sounds like everyone is OK with this, the authoring team is just describing that issue, along with other issues, with the bug disclosure process (like lying about there being no vulnerability while simultaneously fixing it)

Post reply on HN