Earlier quoted context omitted.
Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. I would not be surprised if at least FB and Twitter also had early access. It was clear from the beginning that as soon as the details became public, a race would begin for the script-kiddy-friendliest tool to own sites/users. And the most likely targets of script kiddies should b…
And what about Google? and Amazon? And banks? And .gov sites? I'm not sure how you can handle this in any different way as they did, really.
What Heartbleed Can Teach The OSS Community About Marketing
31–40 of 119 posts
Re: What Heartbleed Can Teach The OSS Community About Marketing
#32"Your bosses / stakeholders / customers / family / etc also cannot immediately understand, on hearing the words “Rails YAML deserialization vulnerability”, that large portions of the Internet nearly died in fire." I watched my colleagues working around the clock (not that bad as it sounds - we are scattered around the planet for a reason) patching servers, testing and ensuring every hatch is properly shut. I can imag…
Marketing works both ways, you know.
Re: What Heartbleed Can Teach The OSS Community About Marketing
#33For example, at our place, "Munin" or recently "Graphite" have been established as the name for our monitoring systems. They describe a system spanning a couple hundreds servers, include a handful of different daemons and configurations and generally, a lot that's going on, so the term is inherently ambiguous and imprecise.
However, I've found that this takes a lot of pressure from the less involved people. They don't need to figure out how to call something precisely and correctly. They have an accepted, not entirely correct term that's precise enough to get the point across: "Munin on Server X broke" is all I need. Similarly, "Is our server X affected by Heartbleed?" might be a silly question because server X is no webserver, but it's easy to answer, because the question is precise enough and just on the right level.
Re: What Heartbleed Can Teach The OSS Community About Marketing
#34Re: What Heartbleed Can Teach The OSS Community About Marketing
#35Maybe MITRE should assign proper names to serious CVEs, kind of like hurricanes?
Oh, great. Then in a few years we can have minor security issues given names, too. Like how winter storms this past winter were called "Polar Vortexes." This world needs less media sensationalism, not more.
Re: What Heartbleed Can Teach The OSS Community About Marketing
#36Earlier quoted context omitted.
Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. I would not be surprised if at least FB and Twitter also had early access. It was clear from the beginning that as soon as the details became public, a race would begin for the script-kiddy-friendliest tool to own sites/users. And the most likely targets of script kiddies should b…
And what about Google? and Amazon? And banks? And .gov sites? I'm not sure how you can handle this in any different way as they did, really.
...independently discovered by a team of security engineers (Riku, Antti and Matti) at Codenomicon and Neel Mehta of Google Security
Re: What Heartbleed Can Teach The OSS Community About Marketing
#37I can't disagree with this post enough. Security exploitations shouldn't be about marketing. Security exploits should be handled first and then communicated to the public after the fact. The way Heartbleed was handled lead to a media firestorm. Other than Codenomic, who else benefitted from this? > Marketing Helps Accomplish Legitimate Goals Are you kidding me? The only goal of a security issue should be fixing it an…
No, a thousand times no. It's pretty obvious big targets would be on top of this. But given the severity of this bug you need to get to the lazy sysadmin, to the small ecommerce owner that doesn't have an on site admin, etc.
The marketing is just confusing people, and patio11's advocacy for more irresponsible marketing-focused disclosure is self-promotional, ambulance chasing, and irresponsible in the extreme.
Small ecommerce owner gets OpenSSL from their hosting vendor. Lazy sysadmin is running 'apt-get update' && 'apt-get install', and if he's not, there are 50 other serious vulnerabilities he's open to anyway.
Re: What Heartbleed Can Teach The OSS Community About Marketing
#38 > Man, would that have been an easier month if
> we had all been talking about DeserialKiller.
Cereal Thief (I like a bit of whimsy; and as a child, it was serious :-)Serial Killer (Yeah, drops the "De", but more people will associate with it, and it's easier to parse and pronounce.)
Re: What Heartbleed Can Teach The OSS Community About Marketing
#39"The Heartbleed announcement ... is masterful communication." You have to be kidding me. It took so long to decipher what I wanted to know that I went elsewhere. Edit: "masterful communication" this is not, since the reader doesn't know who the page is aimed at. Even a line at the top saying "Technical people go _here_", and then something aimed at technical people would be better.
The announcement isn't for technical folks. If you want to know the in depth details then you likely have no issue referring to bugs as numbers, or reading up on the technical details of the exploit. When you announce something you give the information in a form that the public can understand. For example if I announce a new processor, I'll announce its clock speed, number of cores. If I feel like getting in depth ca…
It's not for non-technical folks, either, because there's nothing they can possibly do other than be confused.
It's empty self-promoting marketing that sent the entire industry scrambling.
Re: What Heartbleed Can Teach The OSS Community About Marketing
#40"Your bosses / stakeholders / customers / family / etc also cannot immediately understand, on hearing the words “Rails YAML deserialization vulnerability”, that large portions of the Internet nearly died in fire." I watched my colleagues working around the clock (not that bad as it sounds - we are scattered around the planet for a reason) patching servers, testing and ensuring every hatch is properly shut. I can imag…
You don't think for a second that the reason you were all working so hard to fix this is entirely because of the marketing? The intense marketing of Heartbleed alerted legit crackers (who would have found out anyway), and a thousand times worse, it alerted wannabe crackers of low hanging security exploit fruit. Marketing works both ways, you know.
Serious security vulnerabilities do their own marketing for the people that need to know about them.
This is just lowering security to the tabloid level for mass consumption by users who can't fix the issue anyway.