Live data from Hacker News

Full-disclosure – Administrivia: The End

marc.info

11–20 of 142 posts

Re: Full-disclosure – Administrivia: The End

#11
He doesn't disclose much information, but it looks a bit like he (sourly) blames the industry and community for something that is very common elsewhere too: to run a public forum or mailing list, you now need not only the users' support and goodwill, but also legal counsel, a thick skin and willingness to challenge legal threats, as well as all sorts of technical means to fend of malicious activities (DoS/spam protection etc.).

What's stopping such communities from going "underground", i.e. to some darknet where anonymity and protection from some of these hassles still exists?

Re: Full-disclosure – Administrivia: The End

#14

He doesn't disclose much information, but it looks a bit like he (sourly) blames the industry and community for something that is very common elsewhere too: to run a public forum or mailing list, you now need not only the users' support and goodwill, but also legal counsel, a thick skin and willingness to challenge legal threats, as well as all sorts of technical means to fend of malicious activities (DoS/spam protec…

Nothing -- such underground communities do exist, but then it is no longer a public forum.

Re: Full-disclosure – Administrivia: The End

#15

He doesn't disclose much information, but it looks a bit like he (sourly) blames the industry and community for something that is very common elsewhere too: to run a public forum or mailing list, you now need not only the users' support and goodwill, but also legal counsel, a thick skin and willingness to challenge legal threats, as well as all sorts of technical means to fend of malicious activities (DoS/spam protec…

> What's stopping such communities from going "underground", i.e. to some darknet where anonymity and protection from some of these hassles still exists?

Principle? The whole point of FD was for these discussions to happen in the open.

Re: Full-disclosure – Administrivia: The End

#17
post #16

Wow, this is sad. Hope we can get more info on what was going on. Besides Bugtraq what mailing lists security wise do you follow? EDIT: Or what other general means by Twitter, Websites, Databases, Blogs etc. do you recommend?

Secunia has a free Secunia Weekly Advisory Summary newsletter. You need to register for an account at https://secunia.com/community/profile/ and tick a box for a weekly summary IIRC.

But it's probably easier and more convenient to subscribe for announce mailiing lists for software you're using. Unless you can turn off affected services or scramble and patch before maintainers.

Re: Full-disclosure – Administrivia: The End

#18

He didn't really explain the full problem so maybe I am not fully appreciating the situation here, but this seems like a pretty big overreaction for a stupid request from some a single user.

Are you unfamiliar with the phrase he used, "straw that broke the camel's back"?

In this context, it's really a weasel term. He's functionally given no explanation.

Re: Full-disclosure – Administrivia: The End

#20
post #4

Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?

Full-Disclosure is a popular mailing list that is ostensibly about discussion of vulnerabilities (particularly new ones), but is often as not the security scene's version of 4chan. It was a sort of successor to Bugtraq.
Post reply on HN