Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

121–130 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#121
post #67

Earlier quoted context omitted.

"Responsible" disclosure is an Orwellian term. The real term is "coordinated disclosure", and, as you can see from the timeline, there's coordination here.

"Coordinated disclosure" is the orwellian reimagining here. The only reason why the industry settled on the responsible disclosure process is that works regardless of how much vendor coordination occurs, or even if they are technically responding to emails but really just stalling indefinitely.

No, I was there at the inception of this term, and it was absolutely originally imagined as a way of controlling researchers and giving vendors more power over information about their products. It has pissed researchers off for decades, as it implies that not following the "responsible" process makes one per se "irresponsible".

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#122
post #96

Earlier quoted context omitted.

> Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat I don't think it is upsetting at all. "We found a vulnerability" "There's no vulnerability" "No, you misunderstand, here's how it works and how to exploit" "Naah, no vulnerability" "Ok, if there's no vulnerability as you claim, you don't mind u…

The thing is, "releasing our findings to the public" puts the vendor's customers at risk, it's not just some imagined Just Punishment For The Guilty, innocents get hurt. Imagine if you took a new job and they had a bunch of hardware sitting around from such a vendor. Would you be OK if someone published an exploit for your systems? (In this case, the vulnerability seems minor, so it's sort of academic. But I'm not un…

> puts the vendor's customers at risk

They were already at risk and didn't even know before disclosure. If anyone's to blame for anything, it's the corporation. They were told a vulnerability existed. If it got to the point people are releasing things to the public, it's certainly because they neglected to do what needed to be done.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#123
post #104
post #88

Earlier quoted context omitted.

They pay you money, you disclose exclusively on their terms. That's the deal, and the purpose of the NDA. If you don't like the NDA terms, you don't engage with the bounty program, and you just publish on your own. There's no reasonable way to make a whole big thing out of this.

The only reason it's a "thing" is that the reporters in this case were attempting to do a responsible, coordinated disclosure. That's important for their own brand - many clients would be reluctant to hire a security consultant who just dropped 0days without a damn good reason. So this is documentation and justification for why they did a unilateral disclosure - the expectation is that you "show your work" and be cle…

Nobody is going to avoid hiring a security consultancy that posts bugs with a coordinated timeline that notes they didn't engage with the bounty program.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#124
post #102

Earlier quoted context omitted.

Seriously. I don't think the researcher realizes how many people try to bypass hackerone because H1 would have flagged their finding as invalid. Using h1 isn't about bug bounties, it's about not having to spend a 1-2 of your team's full time engineers triaging security researcher reports.

If H1 was willing to take and triage reports without requiring acceptance of their terms and NDA, that would be fine. We also need to be very clear that the moment a company, or it's authorized representative, flags something as a wontfix or "not a security issue", full and immediate disclosure is fair game.

I think that clarity already exists.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#125

Earlier quoted context omitted.

Seriously. I don't think the researcher realizes how many people try to bypass hackerone because H1 would have flagged their finding as invalid. Using h1 isn't about bug bounties, it's about not having to spend a 1-2 of your team's full time engineers triaging security researcher reports.

Then they should provide a path that doesn't involve arbitrary NDAs if you're willing to forego the reward.

That path already exists: it's called "email security@vendor, tell them what you found, ask when a patch is expected, and then tell them they have 60 days".

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#126

Earlier quoted context omitted.

"Coordinated disclosure" is the orwellian reimagining here. The only reason why the industry settled on the responsible disclosure process is that works regardless of how much vendor coordination occurs, or even if they are technically responding to emails but really just stalling indefinitely.

No, I was there at the inception of this term, and it was absolutely originally imagined as a way of controlling researchers and giving vendors more power over information about their products. It has pissed researchers off for decades, as it implies that not following the "responsible" process makes one per se "irresponsible".

> No, I was there at the inception of this term, and it was absolutely originally imagined as a way of controlling researchers and giving vendors more power over information about their products.

I mean, that half is the carrot to get vendors to play ball and actually fix their shitty code occasionally. It lets unaffiliated white hat security researchers who are just trying to get sec issues fixed actually get some focus time from the various sauron-esque eyes that are corporate attention by converting a 'bug report' into an 'impending pr nightmare bomb with a known timer'. It's a similar hack to complaining on twitter to deal with a marketing department instead of calling in to a customer service line that's just trying to get you to go away.

> It has pissed researchers off for decades, as it implies that not following the "responsible" process makes one per se "irresponsible".

The point of calling it responsible is to defend the researchers who have massively less power in the relationship against the vendors. Even now you'll see whitehats lambasted for eventually disclosing after a vendor dragged their ass. Beyond that, yeah you can't please everyone.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#127
post #10
post #2

That doesn't give me the impression of a company focussed on security. That they marked the installer of the PoC as "malicious" shows they do have a process, but don't take it seriously.

It’s the snake oil industry. They don’t sell security, they sell CISO get out of jail cards in the form of client agents that constantly remind you of their divine presence by being on top of the CPU utilization sorted process list.

I would agree for some of the old guard antivirus (looking at you McCrappy) but with the better ones you are also paying for a huge amount of analytics and reporting. If you are dealing with a breach (even a small one) it can be really really nice (and reassuring especially for people at higher levels) to have nice easy to consume data on what the chain of attack was and where it started.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#128
post #10
post #2

That doesn't give me the impression of a company focussed on security. That they marked the installer of the PoC as "malicious" shows they do have a process, but don't take it seriously.

It’s the snake oil industry. They don’t sell security, they sell CISO get out of jail cards in the form of client agents that constantly remind you of their divine presence by being on top of the CPU utilization sorted process list.

Download and run mimikatz on an endpoint protected by said “snake oil” and one without. Note the difference.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#129

Earlier quoted context omitted.

I feel your pain at a deep and spiritual level. I have been in charge of at least half a dozen endpoint protection products over the years (deployment, configuration, management, etc.). Once a user experiences what you just described they are (rightfully) suspicious and sour towards endpoint protection. Questions i would ask in your example: 1) Was the core business tool excluded from the more intrusive protection mo…

Can I ask, since you're as a person who has administered endpoint protection products: how much legitimate stuff do they actually catch?

I'm not the guy above but the better ones can be very useful. And if they are behaving that badly and impeding your work THAT much then it is most likely that the person in your org configuring it just sucks as their job.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#130
post #67

Earlier quoted context omitted.

> Even modzero themselves admitted that the vulnerability is not of great severity They're wrong. It's not at all uncommon for companies to give employees admin, and privilege escalation tends to be easy on Windows anyway. > CrowdStrike has no obligation in providing them with free trials or such in verifying a vulnerability fix Sure, and modzero has no obligation to responsibly disclose, and now here we are. I'm sur…

"Responsible" disclosure is an Orwellian term. The real term is "coordinated disclosure", and, as you can see from the timeline, there's coordination here.

You're watering down the meaning of Orwellian just a tad here but sure, "responsible" has a value judgment baked in that "coordinated" is mercifully free of. On the other hand, "coordinatedly disclosed" doesn't work as well in a sentence.
Post reply on HN