Live data from Hacker News

Full-disclosure – Administrivia: The End

marc.info

71–80 of 142 posts

Re: Full-disclosure – Administrivia: The End

#71
post #31

He didn't really explain the full problem so maybe I am not fully appreciating the situation here, but this seems like a pretty big overreaction for a stupid request from some a single user.

As someone who had to deal with legal troubles when running a user facing service I can say that it's not that easy if you don't have resources (or knowledge/time) to response correctly to the legal inquiries. For example, a relatively small (by internet standards) "local" forum has a somehow dedicated (it's not their full time job) 3 man legal team that answers all the legal inquiries. If I add one of the latest in…

The only reason legal bullying works is because so many people capitulate at the first sign of conflict.

Re: Full-disclosure – Administrivia: The End

#72
post #48

What a shame; I just recently started taking on an interest in computer security and signed up for the list. In just the few weeks I was on there, I learned about a vulnerability in a device I had recently bought. I am cherishing the opportunity (which I haven't found time for yet) to walk through my first exploit! As a newcomer I'm not really sure what John's referring to, though. Too bad...

I'll offer my take on his "industry that shouldn't have become an industry". One of the biggest drivers of cash into information security hires is government regulation. Otherwise, a lot of these companies could give a shit if they lose private data. Enter the information security specialist who has no fucking clue how to program or do anything remotely technical. They went out and got their CISSP cert, and now they…

I think John's point was more wide-ranging. Even without regulation, the truth is that security has long become just another market, where vulnerabilities and skills are bought and sold for cash, like any other commodity. Security used to be an aspect of system administration; now it's just another rat race with all the trappings of commercialisation ("enterprise" products etc etc).

Re: Full-disclosure – Administrivia: The End

#73
post #10

Earlier quoted context omitted.

Snippets from the mailing list charter[0] and listinfo[1] which simply say briefly: About Full-Disclosure Unlike bugtraq, this list serves no one except the list members themselves We don't believe in security by obscurity, and as far as we know, full disclosure is the only way to ensure that everyone, not just the insiders have access to the information we need to survive. We will try to operate this list without mo…

Given the list's modus operandi and goals, wouldn't it work well under a format such as the blockchain? No moderation and no chance to delete what's been posted, since the decentralization means it would by then be replicated across lots of machines.

Wouldn't that just be Usenet? And how would it avoid the problems that eventually made Usenet worthless as a discussion medium?

Re: Full-disclosure – Administrivia: The End

#75
post #16

Wow, this is sad. Hope we can get more info on what was going on. Besides Bugtraq what mailing lists security wise do you follow? EDIT: Or what other general means by Twitter, Websites, Databases, Blogs etc. do you recommend?

No substitute for email, but VuXML is an interesting, machine-readable, and therefore potentially extremely useful way of distributing security advisories:

http://www.vuxml.org/freebsd/

Re: Full-disclosure – Administrivia: The End

#76
post #39
post #12

Earlier quoted context omitted.

Yes it would seem in the vein of the list to out the 'researcher' who is being the final asshole.

What would be the point, other than nailing that person to a post and having them exposed to various forms of Internet abuse? As you said yourself, this is just the final straw.

The whole point of the list was full disclosure, so that things could not hide in the dark.

Re: Full-disclosure – Administrivia: The End

#77
post #69
post #54

Earlier quoted context omitted.

I floated the idea on bitcointalk.org of a fully anonymous distributed message board that used small bitcoin payments as the cost to post messages ... possibly softened by having a newbie/spam forum where "free" posts are possible but don't get much attention. It didn't get much traction. (I can understand why bitcointalk.org is staying where they are. It was when theymos was openly asking what to do with all the don…

Something like this? http://www.btcmessenger.com/?page=send just filter it for spam like we do with normal email, maybe an application anyone can run instead of a website that can be taken down. Also, is there a provable way to generate a public bitcoin address without learning the private key? As a way to keep it fair.

To what you said: yes. Except to not store the messages in the blockchain, which removes the need to generate a bitcoin address.

However, there are some implementation issues that need to be resolved, e.g. on github.

Re: Full-disclosure – Administrivia: The End

#78
post #71
post #31

Earlier quoted context omitted.

As someone who had to deal with legal troubles when running a user facing service I can say that it's not that easy if you don't have resources (or knowledge/time) to response correctly to the legal inquiries. For example, a relatively small (by internet standards) "local" forum has a somehow dedicated (it's not their full time job) 3 man legal team that answers all the legal inquiries. If I add one of the latest in…

The only reason legal bullying works is because so many people capitulate at the first sign of conflict.

Not sure if you've ever been involved in a suit, but the "first sign of conflict" is a critical juncture. Perhaps the most critical. And, in many cases, your decision is a function of simple math.

Once you proceed past the "first sign of conflict", you will quickly sink a lot of cash. You don't get a refund if you later decide to stop, nor any other credit. That money is gone and either you keep going until you a.) win (or lose) a protracted, costly battle; b.) bankrupt your cash, energy, or will; or c.) find an opportunity to settle and stop the bleeding. By then, the damage is done.

So, if you decide to proceed, then you are signing up for significant cost and a ride for which you have limited control. They will keep throwing stuff at you to entangle and frustrate you. If you take the suit as far as discovery, then you can get into the high 6-figure or even 7-figure range before you know it.

And, before you get to discovery, the motions, counter-motions, and other pleadings can easily get you to six figures within a few short months or less (depending on the complexity of the case).

If you are a small business, it can be a non-starter, especially when the plaintiff is a much larger (and hostile) company. I've been through it personally and I decided not to "capitulate at the first sign of conflict". I was pissed, they were wrong, I wouldn't be bullied, etc. So, I fought it.

We handily beat them back on the initial injunction they were seeking. Based on the merit, we knew we'd win that easily. Still, it cost me ~$20K to actually do it. It doesn't matter how weak their case is. They can make you bleed to prove it. The standard for having the suit labeled frivolous is extraordinarily high and you almost assuredly will not recover your legal fees.

We kept fighting, using some of the foundation (research, etc.) laid during the injunction battle to reduce costs. Still, by the time, we reached the mandatory (in the state of CA) settlement conference (where we decided to settle), we were out over $100K. So, that was the price of "not capitulating at the first sign of conflict". Of course, we didn't have to concede everything they initially demanded, but that small victory felt a bit Pyrrhic.

And, none of this cost includes the time, mental energy, and stress involved. If you are running a small business, you likely don't have time/energy for it. So, beyond literally bankrupting you, it can damage your business (perhaps irreparably) in other ways.

Re: Full-disclosure – Administrivia: The End

#79
post #65

What exactly happened?

Somebody set up us the bomb! Seriously, use 30 seconds to browse, ie http://marc.info/?l=full-disclosure&r=1&b=201403&w=2 Notice 144 posts about "Google vulnerabilities with PoC"?

That's an ugly thread with people putting each other down in every post.

Re: Full-disclosure – Administrivia: The End

#80
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

Yes. This is true. I posted something similar circa 2009 about this sentiment. It used to bother me a lot but not anymore. A reply from pg on the different cultures:

  pg 1678 days ago | link 

  Everything you've written would have been just as true in the 1980s, with a few of the names changed. Then too there were authentic hackers, glib fakers, and corporate drones.

  The great majority of the computer world in the 1980s was profoundly unsubversive. The smart, subversive people were a tiny minority. They seem a larger proportion when you look back from 30 years later, because the fakers and PHBs had no lasting effects.
10 years from now, who is going to remember Marc Andreessen or Paul Graham? Besides some true hacker enthusiast ironically, who remembers Andressen's work on Netscape. In my original post in 2009, I mentioned the hot founder celebrities back then, Carol Bartz (fired), Seth Godin (pumping out more irrelevant books listed further down on Amazon) and Timothy Ferris (moved on from 4-hour "founding" to 4-hour body-building and cooking).

I think in the early nineties, when Linus Torvald first pushed out Linux on the listserv. We had OS/2 Warp and Windows 3.0 preview and Microsoft Bob. Borland, WordPerfect, Lotus 123 running on MS-DOS were the kings. Do you guys remember who founded or worked on those? The people who hack on stuff will always be there because money & fame didn't motivate them in the first place.

Post reply on HN