Live data from Hacker News

Full-disclosure – Administrivia: The End

marc.info

81–90 of 142 posts

Re: Full-disclosure – Administrivia: The End

#81
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

>>> 10-20 years back a term hacker had a close relation to a certain morale conduct emphasizing freedom of knowledge. Agreed. There was a certain "code" people adhered to. Even groups like LOD wouldn't release exploits because they feared people would use them for nefarious purposes.

This is batshit revisionist bullshit. Anyone who close-held an exploit did so to keep the bug alive longer. People routinely burned exploits when they found their rivals using them, not by alerting vendors but by circulating exploit code on #hack

Re: Full-disclosure – Administrivia: The End

#82
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

I don't even know how to respond to the idea that teenagers breaking into phone switches and harassing people, buying Pantera CDs on stolen credit cards, stealing ESNs from other people's phones to make calls on someone else's bill, and rm'ing Unix boxes are somehow more honorable than adults running businesses.

The "hackers" FD's moderator is talking about are the ones I'm talking about. They aren't MIT students ordering sweet and sour bitter melon.

Re: Full-disclosure – Administrivia: The End

#83
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

Yes. This is true. I posted something similar circa 2009 about this sentiment. It used to bother me a lot but not anymore. A reply from pg on the different cultures: pg 1678 days ago | link Everything you've written would have been just as true in the 1980s, with a few of the names changed. Then too there were authentic hackers, glib fakers, and corporate drones. The great majority of the computer world in the 1980s…

> glib fakers, and corporate drones.

Truly PG's lack of self-awareness (or cynical dishonesty) is mind-boggling.

Re: Full-disclosure – Administrivia: The End

#84
post #82
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

I don't even know how to respond to the idea that teenagers breaking into phone switches and harassing people, buying Pantera CDs on stolen credit cards, stealing ESNs from other people's phones to make calls on someone else's bill, and rm'ing Unix boxes are somehow more honorable than adults running businesses. The "hackers" FD's moderator is talking about are the ones I'm talking about. They aren't MIT students ord…

> are somehow more honorable than adults running businesses.

Gotta admit, I thought the same thing. Then I'm reminded of patent and trademark law...

Re: Full-disclosure – Administrivia: The End

#85
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

I am totally confused by your comment. A "hacker" in the context of the Full Disclosure list is a completely different thing than what "hacker" means in the context of Hacker News.

It's at best trying to compare a painter that does portraits to a painter that paints automobiles. Both require skills, but in completely different areas.

Re: Full-disclosure – Administrivia: The End

#86
post #82

Earlier quoted context omitted.

I don't even know how to respond to the idea that teenagers breaking into phone switches and harassing people, buying Pantera CDs on stolen credit cards, stealing ESNs from other people's phones to make calls on someone else's bill, and rm'ing Unix boxes are somehow more honorable than adults running businesses. The "hackers" FD's moderator is talking about are the ones I'm talking about. They aren't MIT students ord…

> are somehow more honorable than adults running businesses. Gotta admit, I thought the same thing. Then I'm reminded of patent and trademark law...

What about it? Patent and trademark law are two things the typical valley "hacker" acutely oppose.

Re: Full-disclosure – Administrivia: The End

#87
A bit of context, maybe it will be helpful for some:

http://seclists.org/fulldisclosure/2014/Mar/170

http://seclists.org/fulldisclosure/2014/Mar/294

http://seclists.org/fulldisclosure/2014/Mar/291

http://seclists.org/fulldisclosure/2014/Mar/286

http://seclists.org/fulldisclosure/2014/Mar/298

And a full email exchange: http://seclists.org/fulldisclosure/2014/Mar/index.html#123

My personal favourite (in a positive way): http://seclists.org/fulldisclosure/2014/Mar/160

Re: Full-disclosure – Administrivia: The End

#88
post #60

Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…

Yes. This is true. I posted something similar circa 2009 about this sentiment. It used to bother me a lot but not anymore. A reply from pg on the different cultures: pg 1678 days ago | link Everything you've written would have been just as true in the 1980s, with a few of the names changed. Then too there were authentic hackers, glib fakers, and corporate drones. The great majority of the computer world in the 1980s…

It reminds me of some lines along those found in this video:

https://www.youtube.com/watch?v=qHE_XGtUNx4

(Wear Sunscreen)

Re: Full-disclosure – Administrivia: The End

#89
post #5
post #4

Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?

Yes (vulnerabilities rather than exploits, although these disclosures often contained proofs of concept.) It was the de facto standard vehicle for this.

No, it was the de facto standard mailing list for releasing vulnerabilities. Over the last 7 years it's gotten less and less relevant as a way of releasing vulnerabilities, because large public mailing lists are not a particularly effective way to publish vulnerabilities.

People seem to believe that happened because vulnerabilities started to obtain a market value, but:

* The serious high-end memory corruption vulnerabilities were (a) more common and (b) much simpler at FD's inception, making them more amenable to posting on a list; in 2014, a high-end vulnerability is likely to be complex enough to merit in-depth consideration on a blog instead.

* Table-stakes XSS vulnerabilities also tend to get written up in blogs (where they help establish a track record for researchers whose future employers aren't going to trawl through FD looking for them), and when they get bought, get bought by bug bounties. It is hard to argue that bug bounties are a bad thing; nobody benefits from a web vulnerability in a SaaS product other than the operator of the SaaS product.

Re: Full-disclosure – Administrivia: The End

#90
post #45

Earlier quoted context omitted.

Hi, I'm posting this through Tor. The reason I'm able to do this is because this account is more than two weeks old. I also created this account through Tor, so HN's operators should have no idea who I am. For example, you have done an experiment below of posting comments through tor using the newly-created account "throughtor": https://news.ycombinator.com/threads?id=throughtor If you turn on "showdead" in your prof…

We switched to bcrypt several years ago.

That's great to hear - thanks for doing so.
Post reply on HN