He didn't really explain the full problem so maybe I am not fully appreciating the situation here, but this seems like a pretty big overreaction for a stupid request from some a single user.
As someone who had to deal with legal troubles when running a user facing service I can say that it's not that easy if you don't have resources (or knowledge/time) to response correctly to the legal inquiries. For example, a relatively small (by internet standards) "local" forum has a somehow dedicated (it's not their full time job) 3 man legal team that answers all the legal inquiries. If I add one of the latest in…
Full-disclosure – Administrivia: The End
71–80 of 142 posts
Re: Full-disclosure – Administrivia: The End
#72What a shame; I just recently started taking on an interest in computer security and signed up for the list. In just the few weeks I was on there, I learned about a vulnerability in a device I had recently bought. I am cherishing the opportunity (which I haven't found time for yet) to walk through my first exploit! As a newcomer I'm not really sure what John's referring to, though. Too bad...
I'll offer my take on his "industry that shouldn't have become an industry". One of the biggest drivers of cash into information security hires is government regulation. Otherwise, a lot of these companies could give a shit if they lose private data. Enter the information security specialist who has no fucking clue how to program or do anything remotely technical. They went out and got their CISSP cert, and now they…
Re: Full-disclosure – Administrivia: The End
#73Earlier quoted context omitted.
Snippets from the mailing list charter[0] and listinfo[1] which simply say briefly: About Full-Disclosure Unlike bugtraq, this list serves no one except the list members themselves We don't believe in security by obscurity, and as far as we know, full disclosure is the only way to ensure that everyone, not just the insiders have access to the information we need to survive. We will try to operate this list without mo…
Given the list's modus operandi and goals, wouldn't it work well under a format such as the blockchain? No moderation and no chance to delete what's been posted, since the decentralization means it would by then be replicated across lots of machines.
Re: Full-disclosure – Administrivia: The End
#74Re: Full-disclosure – Administrivia: The End
#75Wow, this is sad. Hope we can get more info on what was going on. Besides Bugtraq what mailing lists security wise do you follow? EDIT: Or what other general means by Twitter, Websites, Databases, Blogs etc. do you recommend?
Re: Full-disclosure – Administrivia: The End
#76Earlier quoted context omitted.
Yes it would seem in the vein of the list to out the 'researcher' who is being the final asshole.
What would be the point, other than nailing that person to a post and having them exposed to various forms of Internet abuse? As you said yourself, this is just the final straw.
Re: Full-disclosure – Administrivia: The End
#77Earlier quoted context omitted.
I floated the idea on bitcointalk.org of a fully anonymous distributed message board that used small bitcoin payments as the cost to post messages ... possibly softened by having a newbie/spam forum where "free" posts are possible but don't get much attention. It didn't get much traction. (I can understand why bitcointalk.org is staying where they are. It was when theymos was openly asking what to do with all the don…
Something like this? http://www.btcmessenger.com/?page=send just filter it for spam like we do with normal email, maybe an application anyone can run instead of a website that can be taken down. Also, is there a provable way to generate a public bitcoin address without learning the private key? As a way to keep it fair.
However, there are some implementation issues that need to be resolved, e.g. on github.
Re: Full-disclosure – Administrivia: The End
#78Earlier quoted context omitted.
As someone who had to deal with legal troubles when running a user facing service I can say that it's not that easy if you don't have resources (or knowledge/time) to response correctly to the legal inquiries. For example, a relatively small (by internet standards) "local" forum has a somehow dedicated (it's not their full time job) 3 man legal team that answers all the legal inquiries. If I add one of the latest in…
The only reason legal bullying works is because so many people capitulate at the first sign of conflict.
Once you proceed past the "first sign of conflict", you will quickly sink a lot of cash. You don't get a refund if you later decide to stop, nor any other credit. That money is gone and either you keep going until you a.) win (or lose) a protracted, costly battle; b.) bankrupt your cash, energy, or will; or c.) find an opportunity to settle and stop the bleeding. By then, the damage is done.
So, if you decide to proceed, then you are signing up for significant cost and a ride for which you have limited control. They will keep throwing stuff at you to entangle and frustrate you. If you take the suit as far as discovery, then you can get into the high 6-figure or even 7-figure range before you know it.
And, before you get to discovery, the motions, counter-motions, and other pleadings can easily get you to six figures within a few short months or less (depending on the complexity of the case).
If you are a small business, it can be a non-starter, especially when the plaintiff is a much larger (and hostile) company. I've been through it personally and I decided not to "capitulate at the first sign of conflict". I was pissed, they were wrong, I wouldn't be bullied, etc. So, I fought it.
We handily beat them back on the initial injunction they were seeking. Based on the merit, we knew we'd win that easily. Still, it cost me ~$20K to actually do it. It doesn't matter how weak their case is. They can make you bleed to prove it. The standard for having the suit labeled frivolous is extraordinarily high and you almost assuredly will not recover your legal fees.
We kept fighting, using some of the foundation (research, etc.) laid during the injunction battle to reduce costs. Still, by the time, we reached the mandatory (in the state of CA) settlement conference (where we decided to settle), we were out over $100K. So, that was the price of "not capitulating at the first sign of conflict". Of course, we didn't have to concede everything they initially demanded, but that small victory felt a bit Pyrrhic.
And, none of this cost includes the time, mental energy, and stress involved. If you are running a small business, you likely don't have time/energy for it. So, beyond literally bankrupting you, it can damage your business (perhaps irreparably) in other ways.
Re: Full-disclosure – Administrivia: The End
#79Re: Full-disclosure – Administrivia: The End
#80Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
pg 1678 days ago | link
Everything you've written would have been just as true in the 1980s, with a few of the names changed. Then too there were authentic hackers, glib fakers, and corporate drones.
The great majority of the computer world in the 1980s was profoundly unsubversive. The smart, subversive people were a tiny minority. They seem a larger proportion when you look back from 30 years later, because the fakers and PHBs had no lasting effects.
10 years from now, who is going to remember Marc Andreessen or Paul Graham? Besides some true hacker enthusiast ironically, who remembers Andressen's work on Netscape. In my original post in 2009, I mentioned the hot founder celebrities back then, Carol Bartz (fired), Seth Godin (pumping out more irrelevant books listed further down on Amazon) and Timothy Ferris (moved on from 4-hour "founding" to 4-hour body-building and cooking).I think in the early nineties, when Linus Torvald first pushed out Linux on the listserv. We had OS/2 Warp and Windows 3.0 preview and Microsoft Bob. Borland, WordPerfect, Lotus 123 running on MS-DOS were the kings. Do you guys remember who founded or worked on those? The people who hack on stuff will always be there because money & fame didn't motivate them in the first place.