Live data from Hacker News

What Heartbleed Can Teach The OSS Community About Marketing

kalzumeus.com

71–80 of 119 posts

Re: What Heartbleed Can Teach The OSS Community About Marketing

#71
post #57

Earlier quoted context omitted.

Yes, a thousand times yes. The point isn't to market a vulnerability, the point is to get a fix out there. Forcing the entire world to scramble is great marketing, but poor security. Vendors needed time to prep releases and communications; there's tons of confusion flying around out there. Likewise, patio11's trying to capitalize on the awareness to market himself may also be great marketing, but it's bad advice. I d…

How is patio11 using this "to capitalize" and "to market himself"? Anyone who follows him knows that security-related "PSAs" are a staple of his Twitter feed. Combine that with the fact that he writes about marketing on a regular basis and this post is very much par for the course. Both his PSAs and his material on marketing and business are a real service to everyone. That's why they've been so popular on HN for yea…

> Both his PSAs and his material on marketing and business are a real service to everyone. That's why they've been so popular on HN for years.

HN loves startup porn, but how is this any different than how self-help books are marketed?

Distrust anyone who makes a business out of telling other businesses how to be successful in business because of how they're successful in business.

The people who are successful don't have time to run consultancies, and anyone that knows anything about consultancies knows that the lessons you learn there are very different than what's useful and necessary for product companies.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#72
post #63
post #27

Earlier quoted context omitted.

At that point, speed isn't really the issue yet. Heartbleed was in the wild for two years . Would a day or two have made much difference? Highly unlikely. Speed matters after the disclosure, when every petty criminal and script kiddy in the world is suddenly empowered.

I agree with you, but what about the people that knew about this before hand? The article references cloud flair, on their blog it says that they knew about this before the rest of us, who is to say those individuals are not bad guys??

[deleted]

Re: What Heartbleed Can Teach The OSS Community About Marketing

#73
post #45

Earlier quoted context omitted.

Oh, great. Then in a few years we can have minor security issues given names, too. Like how winter storms this past winter were called "Polar Vortexes." This world needs less media sensationalism, not more.

Media sensationalism is important when it's a very serious issue. Security issues of this calibre need more media sensationalism.

That is not sensationalism. Much the opposite.

Giving the appropriate importance to things is part of what makes good journalism.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#74
post #11

Earlier quoted context omitted.

But you did. What the communication accomplished was getting others who otherwise might not have heard about or cared enough to do something to take measures in fixing it. That's an enormous win.

He did because this is the worst internet bug in the past 10 years, not because the page was so masterfully written. Private keys and user passwords/data being disclosed will be cared about by systems administrators even without such a fancy page.

That's my point. Systems administrators will fix security bugs regardless. So there's not really any negative impact on how Heartbleed was "marketed" besides making their job a little bit harder.

I think that cost is outweighed by the significant increase in exposure.

I'm not saying to make it difficult for people to understand the root cause. We should strive for both. But if I had to choose one over the other I think for a bug this big that marketing it as such wins.

The long tail.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#75
post #11

Earlier quoted context omitted.

But you did. What the communication accomplished was getting others who otherwise might not have heard about or cared enough to do something to take measures in fixing it. That's an enormous win.

> That's an enormous win. Compared to what? Awareness and server-side adoption of fixes for issues at this level of criticality is not a problem our industry has. A problem we used to have, however, is people engaging in grandstanding and irresponsible disclosure, leaving users insecure and catching the industry flat-footed. Empty scare marketing is a solution to a problem we don't have. It's also a great tool for se…

> Awareness and server-side adoption of fixes for issues at this level of criticality is not a problem our industry has.

I probably don't agree with that. I think there are plenty of systems in our industry that aren't actively maintained and don't have dedicated ops to manage them. A fix to a bug this large in magnitude needs to find their way onto those systems.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#76
post #29

"Your bosses / stakeholders / customers / family / etc also cannot immediately understand, on hearing the words “Rails YAML deserialization vulnerability”, that large portions of the Internet nearly died in fire." I watched my colleagues working around the clock (not that bad as it sounds - we are scattered around the planet for a reason) patching servers, testing and ensuring every hatch is properly shut. I can imag…

You don't think for a second that the reason you were all working so hard to fix this is entirely because of the marketing? The intense marketing of Heartbleed alerted legit crackers (who would have found out anyway), and a thousand times worse, it alerted wannabe crackers of low hanging security exploit fruit. Marketing works both ways, you know.

Intense marketing forces everyone to fix the problem because every bad guy has just been told about the vulnerability. But one could reasonably argue that it's better than let the process drag for days, weeks or months, with all the serious bad guys still knowing about the issue (don't believe for a second that secret disclosure to vendors won't leak immediately to some criminal darknets).

Unfortunately, sometimes you need to force people into doing things for their own benefit.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#77
The one weak point of the landing page is that it didn't indicate who was not affected. I read to the bottom of the announcement and had to think a while on whether I had to update my laptop because, hey, this seems like a serious bug. Granted, I'm nontechnical... but that's kind of the point.

Edit: not sure why this was downvoted, but if it contains an error please add a comment pointing it out. If you just think it should be lower on the page, no worries.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#78
post #30
post #4

Ironic that the blog talking about this is a rather boring looking site that I've just navigated away from as soon as I got the gist. Not meaning to be hash but that's what I did...

Not really sure how it's possible to hang out on HN and not know who patio11/Patrick/Kalzumeus is...

I've seen people not know who "pg" is, so...

Re: What Heartbleed Can Teach The OSS Community About Marketing

#79

I can't disagree with this post enough. Security exploitations shouldn't be about marketing. Security exploits should be handled first and then communicated to the public after the fact. The way Heartbleed was handled lead to a media firestorm. Other than Codenomic, who else benefitted from this? > Marketing Helps Accomplish Legitimate Goals Are you kidding me? The only goal of a security issue should be fixing it an…

Yes, a thousand times yes. The point isn't to market a vulnerability, the point is to get a fix out there. Forcing the entire world to scramble is great marketing, but poor security. Vendors needed time to prep releases and communications; there's tons of confusion flying around out there. Likewise, patio11's trying to capitalize on the awareness to market himself may also be great marketing, but it's bad advice. I d…

I believe that in this case marketing is a great way to get a fix out there. It's a commitment act, Schelling-style [0]. They basically forced everybody in the world to drop everything and fix this issue right fucking now. The seriousness of Heartbleed warrants that level of marketing, IMO.

[0] - http://en.wikipedia.org/wiki/Thomas_Schelling#The_Strategy_o...

Re: What Heartbleed Can Teach The OSS Community About Marketing

#80
post #68

Earlier quoted context omitted.

I may very well run a service that my customers' bodily safety depends on the encryption of the SSL connection If that is the case, your FMEA needs to include undisclosed vulnerabilities in your communication channel's encryption, and the mitigation can't be telling the internet your particular opinions on responsible disclosure.

Whew. Good thing I don't run such a service. :-) (Edited my comment to better emphasize that it was hypothetical.)

I knew it was hypothetical, I was just building off my experience with this as a reality and not a thought experiment. I think that your hypothetical is useless to this conversation. The seriousness of death is a good argument tool, but using it in the context of responsible disclosure is theatrics.

Arguing for people with privileged access to the exploit to behave the way you want when disclosing it, is a lot like arguing that people with privileged access to the exploit behave the way you want when exploiting it (ie: don't exploit). When human safety relies on an encrypted channel, you have no option but to assume people aren't going to act the way you want. If you could get people to act the way you want, you wouldn't need to use an encrypted channel in the first place.

Post reply on HN