Today is a sad day. I wonder what will replace full-disclosure as the de-facto vehicle to announce vulnerabilities.
Full-disclosure – Administrivia: The End
61–70 of 142 posts
Re: Full-disclosure – Administrivia: The End
#62Earlier quoted context omitted.
What would be the point, other than nailing that person to a post and having them exposed to various forms of Internet abuse? As you said yourself, this is just the final straw.
That would be the point.
Re: Full-disclosure – Administrivia: The End
#63Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
Re: Full-disclosure – Administrivia: The End
#64Earlier quoted context omitted.
Snippets from the mailing list charter[0] and listinfo[1] which simply say briefly: About Full-Disclosure Unlike bugtraq, this list serves no one except the list members themselves We don't believe in security by obscurity, and as far as we know, full disclosure is the only way to ensure that everyone, not just the insiders have access to the information we need to survive. We will try to operate this list without mo…
Given the list's modus operandi and goals, wouldn't it work well under a format such as the blockchain? No moderation and no chance to delete what's been posted, since the decentralization means it would by then be replicated across lots of machines.
The ledger could provide some assurances that others have had access to a given set of messages, but that really only helps with the boring sort of arguments.
Re: Full-disclosure – Administrivia: The End
#65What exactly happened?
Seriously, use 30 seconds to browse, ie http://marc.info/?l=full-disclosure&r=1&b=201403&w=2
Notice 144 posts about "Google vulnerabilities with PoC"?
Re: Full-disclosure – Administrivia: The End
#66Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
Re: Full-disclosure – Administrivia: The End
#67Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
But it's not the point.
Full-disclosure is all of security-hackers. And the sad thing is that there is no more honour amongst security-hackers. In the 90s they used to share 0-days. Today, well if you don't sell it you're a fool.
I'm so sad I missed that period, IRC, the lulz.
Don't confuse the hacker spirit with the hacker word.
Re: Full-disclosure – Administrivia: The End
#68Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
Agreed.
There was a certain "code" people adhered to. Even groups like LOD wouldn't release exploits because they feared people would use them for nefarious purposes.
Re: Full-disclosure – Administrivia: The End
#69Earlier quoted context omitted.
Hi, I'm posting this through Tor. The reason I'm able to do this is because this account is more than two weeks old. I also created this account through Tor, so HN's operators should have no idea who I am. For example, you have done an experiment below of posting comments through tor using the newly-created account "throughtor": https://news.ycombinator.com/threads?id=throughtor If you turn on "showdead" in your prof…
I floated the idea on bitcointalk.org of a fully anonymous distributed message board that used small bitcoin payments as the cost to post messages ... possibly softened by having a newbie/spam forum where "free" posts are possible but don't get much attention. It didn't get much traction. (I can understand why bitcointalk.org is staying where they are. It was when theymos was openly asking what to do with all the don…
Also, is there a provable way to generate a public bitcoin address without learning the private key? As a way to keep it fair.
Re: Full-disclosure – Administrivia: The End
#70Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?