Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…
> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…
Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
91–100 of 167 posts
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#92Earlier quoted context omitted.
I feel your pain at a deep and spiritual level. I have been in charge of at least half a dozen endpoint protection products over the years (deployment, configuration, management, etc.). Once a user experiences what you just described they are (rightfully) suspicious and sour towards endpoint protection. Questions i would ask in your example: 1) Was the core business tool excluded from the more intrusive protection mo…
Can I ask, since you're as a person who has administered endpoint protection products: how much legitimate stuff do they actually catch?
However what I see is essentially their true positive and false negative rate, I would be interested to know what the false positive rate is.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#93Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…
> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…
I don't think it is upsetting at all.
"We found a vulnerability"
"There's no vulnerability"
"No, you misunderstand, here's how it works and how to exploit"
"Naah, no vulnerability"
"Ok, if there's no vulnerability as you claim, you don't mind us releasing our findings to the public, right?"
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#94Earlier quoted context omitted.
It’s the snake oil industry. They don’t sell security, they sell CISO get out of jail cards in the form of client agents that constantly remind you of their divine presence by being on top of the CPU utilization sorted process list.
There is a LOT of snake oil in the industry, but endpoint protection IS useful. Not every person is a Hacker News reading tech enthusiast. People download and do dumb shit. That is not to say every device needs it and at a max “check every process/file activity” level, though.
In practice, most implementations cause more harm than good. Some of them even add vulnerabilities themselves.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#95Sounds like they expect everyone to be out for a bounty rather than to improve someone else's software so they probably have a contract with HackerOne to let them do all the annoying hard work dealing with security researchers. Personally, I would've released the PoC back in July when they said the problem was resolved. No need to ask if the quote can be used, it's exactly what they told the security researchers afte…
> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#96Earlier quoted context omitted.
> Personally, I would've released the PoC back in July when they said the problem was resolved. Dropping a zero day on the public is never acceptable, regardless of how disingenuous a device manufacturer is being. Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat ("As the issue was not considere…
> Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat I don't think it is upsetting at all. "We found a vulnerability" "There's no vulnerability" "No, you misunderstand, here's how it works and how to exploit" "Naah, no vulnerability" "Ok, if there's no vulnerability as you claim, you don't mind u…
Imagine if you took a new job and they had a bunch of hardware sitting around from such a vendor. Would you be OK if someone published an exploit for your systems?
(In this case, the vulnerability seems minor, so it's sort of academic. But I'm not understanding the mindset of the people here who want to see this as a two party adversarial kind of relationship between Modzero and CrowdStrike. It's not!)
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#97Earlier quoted context omitted.
Sounds more like these companies are using bounty programs to get researchers to sign NDAs so that they can control public perception of their products. Effectively paying people (and heaping ego gratification on top of that) to be silent about found vulnerabilities.
Well, sure. That's essentially the trade you're making with a bounty program: you pay people for finding stuff, and get to establish terms for disclosure. If you're not OK with those terms, you can almost always just ignore the bounty and publish directly.
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#98Earlier quoted context omitted.
Well, sure. That's essentially the trade you're making with a bounty program: you pay people for finding stuff, and get to establish terms for disclosure. If you're not OK with those terms, you can almost always just ignore the bounty and publish directly.
Is there still a safe harbor if you go that route?
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#99Earlier quoted context omitted.
> Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat I don't think it is upsetting at all. "We found a vulnerability" "There's no vulnerability" "No, you misunderstand, here's how it works and how to exploit" "Naah, no vulnerability" "Ok, if there's no vulnerability as you claim, you don't mind u…
The thing is, "releasing our findings to the public" puts the vendor's customers at risk, it's not just some imagined Just Punishment For The Guilty, innocents get hurt. Imagine if you took a new job and they had a bunch of hardware sitting around from such a vendor. Would you be OK if someone published an exploit for your systems? (In this case, the vulnerability seems minor, so it's sort of academic. But I'm not un…
Modzero was even following a more conservative playbook here: not setting a deadline from the start, but only talking about release once the vendor indicated there was no issue (anymore).
Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor
#100Earlier quoted context omitted.
if they have a disclosure process, what purpose is served by the non-disclosure agreement? what with non-disclosure being literally the opposite of disclosure & everything
They pay you money, you disclose exclusively on their terms. That's the deal, and the purpose of the NDA. If you don't like the NDA terms, you don't engage with the bounty program, and you just publish on your own. There's no reasonable way to make a whole big thing out of this.
that is precisely the choice made by the team in the article, because the NDA was bad, for the reasons you described
so it sounds like everyone is OK with this, the authoring team is just describing that issue, along with other issues, with the bug disclosure process (like lying about there being no vulnerability while simultaneously fixing it)