Live data from Hacker News

Full-disclosure – Administrivia: The End

marc.info

21–30 of 142 posts

Re: Full-disclosure – Administrivia: The End

#21
post #16

Wow, this is sad. Hope we can get more info on what was going on. Besides Bugtraq what mailing lists security wise do you follow? EDIT: Or what other general means by Twitter, Websites, Databases, Blogs etc. do you recommend?

Why would you follow any mailing lists for security in 2014? The concept of a security mailing list predates Twitter, vulnerability databases, Reddit, and blogs. But we have all those things now, and they are all better than Full-Disclosure on its best days.

Re: Full-disclosure – Administrivia: The End

#23

Earlier quoted context omitted.

Are you unfamiliar with the phrase he used, "straw that broke the camel's back"?

In this context, it's really a weasel term. He's functionally given no explanation.

Seems pretty clear - burnout. After 12 years of abuse he's had enough.

Re: Full-disclosure – Administrivia: The End

#24

Would anyone mind explaining to me as a noob what kind of legal challenges public lists need to defend against these days? Spam, trolls and politics are not new, but legal threats and DoS attacks I didn't expect to be problems.

Some companies like to practice 'security by obscurity' to the fullest. They sometimes try to keep bugs from being disclosed by researchers using various means of ignore up to legal threats or other non disclosure contracts.

Often when things are at a really bad state its in the public interest to make sure these issues get fixed rather than brushed under the carpet. Hence it gets posted on various sec ML lists to ramp up pressure.

Re: Full-disclosure – Administrivia: The End

#25
post #21
post #16

Wow, this is sad. Hope we can get more info on what was going on. Besides Bugtraq what mailing lists security wise do you follow? EDIT: Or what other general means by Twitter, Websites, Databases, Blogs etc. do you recommend?

Why would you follow any mailing lists for security in 2014? The concept of a security mailing list predates Twitter, vulnerability databases, Reddit, and blogs. But we have all those things now, and they are all better than Full-Disclosure on its best days.

Yeah people keep telling me mail is dead, but its still kicking around and is very well alive. Let me edit my initial question to be email neutral though.

Re: Full-disclosure – Administrivia: The End

#26
Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet.

It is unfortunate that HN is not numbered among those sites.

Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

Re: Full-disclosure – Administrivia: The End

#27

Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

Don't trust Tor to provide anonymity against government adversaries. It's likely not secure given Snowden disclosure of anti-Tor tools.

Re: Full-disclosure – Administrivia: The End

#28

Earlier quoted context omitted.

Are you unfamiliar with the phrase he used, "straw that broke the camel's back"?

In this context, it's really a weasel term. He's functionally given no explanation.

It's a message to his listserv users, not a press release. More context can be found in the archives, or from someone who follows the list closely.

Re: Full-disclosure – Administrivia: The End

#30

Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

>It is unfortunate that HN is not numbered among those sites.

Why do you think that? I'm posting from tor with a fresh throwaway account.

Post reply on HN