Live data from Hacker News

What Heartbleed Can Teach The OSS Community About Marketing

kalzumeus.com

51–60 of 119 posts

Re: What Heartbleed Can Teach The OSS Community About Marketing

#51

Earlier quoted context omitted.

The announcement isn't for technical folks. If you want to know the in depth details then you likely have no issue referring to bugs as numbers, or reading up on the technical details of the exploit. When you announce something you give the information in a form that the public can understand. For example if I announce a new processor, I'll announce its clock speed, number of cores. If I feel like getting in depth ca…

> The announcement isn't for technical folks. It's not for non-technical folks, either, because there's nothing they can possibly do other than be confused. It's empty self-promoting marketing that sent the entire industry scrambling.

Clearly technical and non-technical understand is a binary relationship. Is there a grey zone of understanding when it comes to Transport Layer Encryption?

I figure there is because most of the HN community inhabits it, and I most certainly do.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#52
post #24

Earlier quoted context omitted.

Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. I would not be surprised if at least FB and Twitter also had early access. It was clear from the beginning that as soon as the details became public, a race would begin for the script-kiddy-friendliest tool to own sites/users. And the most likely targets of script kiddies should b…

> Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. AWS is at least as important, as is Akamai. My point being, it's not enough to hand-wave about who's the biggest and most important. A good system would give anyone with enough at risk a clear path to earn a seat at the table. Major providers could create an "early warning discl…

Akamai was notified and completed the patch in advance of public disclosure according to their Heartbleed FAQ: https://blogs.akamai.com/2014/04/heartbleed-faq-akamai-syste...

This raises the question about whether Amazon/AWS was notified prior to public disclosure.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#53
post #9

Maybe MITRE should assign proper names to serious CVEs, kind of like hurricanes?

Oh, great. Then in a few years we can have minor security issues given names, too. Like how winter storms this past winter were called "Polar Vortexes." This world needs less media sensationalism, not more.

They can just use NSA-style semi-random codenames. Every CVE can be automatically assigned a pair of words out of a hat. It'll be particularly beautiful when combined with already-silly software names. I want to have to tell my boss that Raring Ringtail has been affected by Nevada Horseshoe or somesuch.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#54
post #44

Earlier quoted context omitted.

Any result other than "the entire industry scrambling" following the public disclosure of Heartbleed would have been a failure case. How do you imagine that working out? "We need to patch millions of servers managed by hundreds of thousands of people. It all needs to happen today, and be conducted in total secrecy, because if any bad guy finds out about what we're doing there will bet net-wide exploitation by botnets…

You're demonstrating no understanding of how these things work. For updates to be deployed, the patches need to be integrated, tested, packages/updates build, and the update mechanisms tested. For complex systems -- like, say, embedded hardware -- this might involve targeting quite a few different devices and testing matrixes. Even scrambling, this can take days, and leaves users blowing in the wind in the meantime.…

I'm the guy who had to do it at my company, and in a previous career I'd be the boots-on-the-ground dealing with it at a rather larger company. I understand that vendors want a few weeks. I have lived the reality of ponderous engineering processes which need weeks to approve the smallest imaginable change. The for loop does not care what we want and does not get slower at counting to big numbers just because we are slow at counting to small numbers.

I understand that vendors find it inconvenient to field questions from users like "Are you vulnerable to Heartbleed?", most particularly when they are, in fact, vulnerable to Heartbleed. I respect that Yahoo feels embarrassed that there is a screenshot showing usernames and passwords in the clear. I think that the feelings of Yahoo users who would be discomfited that their email accounts are available to anyone with a command line deserves at least as much deference.

I also think it is a radically borked threat model which suggests that attackers only find out about vulnerabilities when the man-on-the-street does rather than when really-savvy-vendor-folk do.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#55
post #49

I can't disagree with this post enough. Security exploitations shouldn't be about marketing. Security exploits should be handled first and then communicated to the public after the fact. The way Heartbleed was handled lead to a media firestorm. Other than Codenomic, who else benefitted from this? > Marketing Helps Accomplish Legitimate Goals Are you kidding me? The only goal of a security issue should be fixing it an…

Who is "the public" here? Why should package maintainers be hearing about this any sooner than me? I may not help maintain a popular Linux distribution, but I may very well run a service that my customers' bodily safety depends on the encryption of the SSL connection. (Hypothetical.) After disclosure, my only option is not to wait for a fix from my vendors and service providers, but to shut down my service (and lock…

> Why should package maintainers be hearing about this any sooner than me?

Because they vend updates to the vast majority of users. It's about maximizing people's ability to get the fix quickly upon public disclosure.

> ... they needed to take action, which in this world of plentiful managed hosting, is really not typical.

What action do you think you need to take? Revoking certificates? Almost nothing checks OCSP or CRLs anyway, there's hardly a rush.

All this marketing has done is sent ill-informed people scurrying.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#56
post #46

Earlier quoted context omitted.

Yes, a thousand times yes. The point isn't to market a vulnerability, the point is to get a fix out there. Forcing the entire world to scramble is great marketing, but poor security. Vendors needed time to prep releases and communications; there's tons of confusion flying around out there. Likewise, patio11's trying to capitalize on the awareness to market himself may also be great marketing, but it's bad advice. I d…

Wait, surely getting everyone to scramble is a good way to get the fix released soon?

Marketing is entirely the wrong way to get the people who release fixes to scramble. At least at the top few tiers (package developers and distribution maintainers) you know the organizations necessary to contact, and how to contact them. If the orgs are worth their salt, a descriptive email to their security contacts is faster and easier than a marketing campaign.

Marketing is useful to get sysadmins too lazy to subscribe to security announcement mailing lists to apply the already-released patches or take other mitigation.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#57

I can't disagree with this post enough. Security exploitations shouldn't be about marketing. Security exploits should be handled first and then communicated to the public after the fact. The way Heartbleed was handled lead to a media firestorm. Other than Codenomic, who else benefitted from this? > Marketing Helps Accomplish Legitimate Goals Are you kidding me? The only goal of a security issue should be fixing it an…

Yes, a thousand times yes. The point isn't to market a vulnerability, the point is to get a fix out there. Forcing the entire world to scramble is great marketing, but poor security. Vendors needed time to prep releases and communications; there's tons of confusion flying around out there. Likewise, patio11's trying to capitalize on the awareness to market himself may also be great marketing, but it's bad advice. I d…

How is patio11 using this "to capitalize" and "to market himself"? Anyone who follows him knows that security-related "PSAs" are a staple of his Twitter feed. Combine that with the fact that he writes about marketing on a regular basis and this post is very much par for the course. Both his PSAs and his material on marketing and business are a real service to everyone. That's why they've been so popular on HN for years.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#58

I can't disagree with this post enough. Security exploitations shouldn't be about marketing. Security exploits should be handled first and then communicated to the public after the fact. The way Heartbleed was handled lead to a media firestorm. Other than Codenomic, who else benefitted from this? > Marketing Helps Accomplish Legitimate Goals Are you kidding me? The only goal of a security issue should be fixing it an…

Yes, a thousand times yes. The point isn't to market a vulnerability, the point is to get a fix out there. Forcing the entire world to scramble is great marketing, but poor security. Vendors needed time to prep releases and communications; there's tons of confusion flying around out there. Likewise, patio11's trying to capitalize on the awareness to market himself may also be great marketing, but it's bad advice. I d…

Part of getting the fix out there is marketing. If the fix is out there and no one knows about it, or the powers that be don't care, what good is the fix?

Re: What Heartbleed Can Teach The OSS Community About Marketing

#59
post #54

Earlier quoted context omitted.

You're demonstrating no understanding of how these things work. For updates to be deployed, the patches need to be integrated, tested, packages/updates build, and the update mechanisms tested. For complex systems -- like, say, embedded hardware -- this might involve targeting quite a few different devices and testing matrixes. Even scrambling, this can take days, and leaves users blowing in the wind in the meantime.…

I'm the guy who had to do it at my company, and in a previous career I'd be the boots-on-the-ground dealing with it at a rather larger company. I understand that vendors want a few weeks. I have lived the reality of ponderous engineering processes which need weeks to approve the smallest imaginable change. The for loop does not care what we want and does not get slower at counting to big numbers just because we are s…

This isn't about inconvenience, it's about having patches in user's hands the moment the vulnerability hits the public.

> I also think it is a radically borked threat model which suggests that attackers only find out about vulnerabilities when the man-on-the-street does rather than when really-savvy-vendor-folk do.

And yet, this is true. A small number of people with a vulnerability provides a small threat exposure, because their attacks are simply more likely to be targeted.

Everyone with a vulnerability provides a large threat exposure, because suddenly every single script kiddie on the planet had a window to target a Python script at Yahoo or GitHub or Amazon and troll through web server's memory.

You think it was worth exposing GitHub's private company repositories to every script kiddie on earth, just because a small number of people had an incredibly valuable zero-day that they would wish to hold in reserve for high priority targets, lest it get burned and they lose the zero-day?

Re: What Heartbleed Can Teach The OSS Community About Marketing

#60
post #49

I can't disagree with this post enough. Security exploitations shouldn't be about marketing. Security exploits should be handled first and then communicated to the public after the fact. The way Heartbleed was handled lead to a media firestorm. Other than Codenomic, who else benefitted from this? > Marketing Helps Accomplish Legitimate Goals Are you kidding me? The only goal of a security issue should be fixing it an…

Who is "the public" here? Why should package maintainers be hearing about this any sooner than me? I may not help maintain a popular Linux distribution, but I may very well run a service that my customers' bodily safety depends on the encryption of the SSL connection. (Hypothetical.) After disclosure, my only option is not to wait for a fix from my vendors and service providers, but to shut down my service (and lock…

I may very well run a service that my customers' bodily safety depends on the encryption of the SSL connection

If that is the case, your FMEA needs to include undisclosed vulnerabilities in your communication channel's encryption, and the mitigation can't be telling the internet your particular opinions on responsible disclosure.

Post reply on HN