Live data from Hacker News

What Heartbleed Can Teach The OSS Community About Marketing

kalzumeus.com

21–30 of 119 posts

Re: What Heartbleed Can Teach The OSS Community About Marketing

#21

I can't disagree with this post enough. Security exploitations shouldn't be about marketing. Security exploits should be handled first and then communicated to the public after the fact. The way Heartbleed was handled lead to a media firestorm. Other than Codenomic, who else benefitted from this? > Marketing Helps Accomplish Legitimate Goals Are you kidding me? The only goal of a security issue should be fixing it an…

Yes, a thousand times yes. The point isn't to market a vulnerability, the point is to get a fix out there.

Forcing the entire world to scramble is great marketing, but poor security. Vendors needed time to prep releases and communications; there's tons of confusion flying around out there.

Likewise, patio11's trying to capitalize on the awareness to market himself may also be great marketing, but it's bad advice.

I don't know why parent is being downvoted, either. This is simply not how you keep people secure. This is how you grandstand to promote yourself at the cost of other people's security.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#22
post #8

"The Heartbleed announcement ... is masterful communication." You have to be kidding me. It took so long to decipher what I wanted to know that I went elsewhere. Edit: "masterful communication" this is not, since the reader doesn't know who the page is aimed at. Even a line at the top saying "Technical people go _here_", and then something aimed at technical people would be better.

Where? And if Heartbleed took to long to figure out, how long did it take to decipher other security vulnerabilities? Don't compare it to a landing page of a consumer service, compare it to most other OSS announcements and projects.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#23
post #13

Yes entirely on name, visual identity and first three paragraphs. More like this for serious vulns, please. Also, what a great name. The remaining of the page is a loud reminder of the gap between the sec and dev communities, at least as practiced in lolstartupland. Or at least between offence and defence. The second paragraph tells you the sky is falling, and then it takes them 13 questions to tell you which openssl…

Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. I would not be surprised if at least FB and Twitter also had early access. It was clear from the beginning that as soon as the details became public, a race would begin for the script-kiddy-friendliest tool to own sites/users. And the most likely targets of script kiddies should b…

And what about Google? and Amazon? And banks? And .gov sites?

I'm not sure how you can handle this in any different way as they did, really.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#24
post #13

Yes entirely on name, visual identity and first three paragraphs. More like this for serious vulns, please. Also, what a great name. The remaining of the page is a loud reminder of the gap between the sec and dev communities, at least as practiced in lolstartupland. Or at least between offence and defence. The second paragraph tells you the sky is falling, and then it takes them 13 questions to tell you which openssl…

Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. I would not be surprised if at least FB and Twitter also had early access. It was clear from the beginning that as soon as the details became public, a race would begin for the script-kiddy-friendliest tool to own sites/users. And the most likely targets of script kiddies should b…

> Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it.

AWS is at least as important, as is Akamai.

My point being, it's not enough to hand-wave about who's the biggest and most important. A good system would give anyone with enough at risk a clear path to earn a seat at the table.

Major providers could create an "early warning disclosure club", each contributing some money annually, and the money can be used to pay bounties to anyone who gives them advance warning of a zero day. Of course you'd want some safeguards to make sure nobody blackhat joins the club to use the vulnerabilities for offense.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#25

I can't disagree with this post enough. Security exploitations shouldn't be about marketing. Security exploits should be handled first and then communicated to the public after the fact. The way Heartbleed was handled lead to a media firestorm. Other than Codenomic, who else benefitted from this? > Marketing Helps Accomplish Legitimate Goals Are you kidding me? The only goal of a security issue should be fixing it an…

No, a thousand times no. It's pretty obvious big targets would be on top of this. But given the severity of this bug you need to get to the lazy sysadmin, to the small ecommerce owner that doesn't have an on site admin, etc.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#26

I agree with the principle; the logo even made the NYT, which had at least three stories on Heartbleed. But: are there enough two-english-word combinations left as viable .com names, much less ones that accurately describe the vulnerability?

A .bug TLD may actually work here.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#27
post #14

I just worry next time when a major incident occurs the author will spend more time working on the design than just announcing the issue.

At that point, speed isn't really the issue yet. Heartbleed was in the wild for two years. Would a day or two have made much difference? Highly unlikely.

Speed matters after the disclosure, when every petty criminal and script kiddy in the world is suddenly empowered.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#28

I can't disagree with this post enough. Security exploitations shouldn't be about marketing. Security exploits should be handled first and then communicated to the public after the fact. The way Heartbleed was handled lead to a media firestorm. Other than Codenomic, who else benefitted from this? > Marketing Helps Accomplish Legitimate Goals Are you kidding me? The only goal of a security issue should be fixing it an…

Yes, a thousand times yes. The point isn't to market a vulnerability, the point is to get a fix out there. Forcing the entire world to scramble is great marketing, but poor security. Vendors needed time to prep releases and communications; there's tons of confusion flying around out there. Likewise, patio11's trying to capitalize on the awareness to market himself may also be great marketing, but it's bad advice. I d…

"Likewise, patio11's trying to capitalize on the awareness to market himself"

That's what I took away from this as well.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#29
"Your bosses / stakeholders / customers / family / etc also cannot immediately understand, on hearing the words “Rails YAML deserialization vulnerability”, that large portions of the Internet nearly died in fire."

I watched my colleagues working around the clock (not that bad as it sounds - we are scattered around the planet for a reason) patching servers, testing and ensuring every hatch is properly shut. I can imagine other teams all over the world and all over the internet doing the same, literally saving our civilization from a threat only a tiny percentage of the population had any idea existed and an even smaller group has any idea of how it threatened us.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#30
post #4

Ironic that the blog talking about this is a rather boring looking site that I've just navigated away from as soon as I got the gist. Not meaning to be hash but that's what I did...

Not really sure how it's possible to hang out on HN and not know who patio11/Patrick/Kalzumeus is...
Post reply on HN