Live data from Hacker News

Full-disclosure – Administrivia: The End

marc.info

61–70 of 142 posts

Re: Full-disclosure – Administrivia: The End

#62
post #39

Earlier quoted context omitted.

What would be the point, other than nailing that person to a post and having them exposed to various forms of Internet abuse? As you said yourself, this is just the final straw.

That would be the point.

Are you suggesting this is a good custom and should be practised?

Re: Full-disclosure – Administrivia: The End

#63
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

[deleted]

Re: Full-disclosure – Administrivia: The End

#64
post #10

Earlier quoted context omitted.

Snippets from the mailing list charter[0] and listinfo[1] which simply say briefly: About Full-Disclosure Unlike bugtraq, this list serves no one except the list members themselves We don't believe in security by obscurity, and as far as we know, full disclosure is the only way to ensure that everyone, not just the insiders have access to the information we need to survive. We will try to operate this list without mo…

Given the list's modus operandi and goals, wouldn't it work well under a format such as the blockchain? No moderation and no chance to delete what's been posted, since the decentralization means it would by then be replicated across lots of machines.

You don't need the complexity of a unified ledger to have a distributed message passing system.

The ledger could provide some assurances that others have had access to a given set of messages, but that really only helps with the boring sort of arguments.

Re: Full-disclosure – Administrivia: The End

#66
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

[deleted]

Re: Full-disclosure – Administrivia: The End

#67
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

Here you are speaking about the two different meanings of hacker, security-hacker and startup-hacker. Yes, there is a big difference, and you described it.

But it's not the point.

Full-disclosure is all of security-hackers. And the sad thing is that there is no more honour amongst security-hackers. In the 90s they used to share 0-days. Today, well if you don't sell it you're a fool.

I'm so sad I missed that period, IRC, the lulz.

Don't confuse the hacker spirit with the hacker word.

Re: Full-disclosure – Administrivia: The End

#68
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

>>> 10-20 years back a term hacker had a close relation to a certain morale conduct emphasizing freedom of knowledge.

Agreed.

There was a certain "code" people adhered to. Even groups like LOD wouldn't release exploits because they feared people would use them for nefarious purposes.

Re: Full-disclosure – Administrivia: The End

#69
post #54

Earlier quoted context omitted.

Hi, I'm posting this through Tor. The reason I'm able to do this is because this account is more than two weeks old. I also created this account through Tor, so HN's operators should have no idea who I am. For example, you have done an experiment below of posting comments through tor using the newly-created account "throughtor": https://news.ycombinator.com/threads?id=throughtor If you turn on "showdead" in your prof…

I floated the idea on bitcointalk.org of a fully anonymous distributed message board that used small bitcoin payments as the cost to post messages ... possibly softened by having a newbie/spam forum where "free" posts are possible but don't get much attention. It didn't get much traction. (I can understand why bitcointalk.org is staying where they are. It was when theymos was openly asking what to do with all the don…

Something like this? http://www.btcmessenger.com/?page=send just filter it for spam like we do with normal email, maybe an application anyone can run instead of a website that can be taken down.

Also, is there a provable way to generate a public bitcoin address without learning the private key? As a way to keep it fair.

Re: Full-disclosure – Administrivia: The End

#70
post #4

Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?

Hehe, nope. It's the list where exploits and vulns are dropped, without getting into the circus and the money of responsible-coordinated-whatever. It's old style. It couldn't survive.
Post reply on HN