Live data from Hacker News

What Heartbleed Can Teach The OSS Community About Marketing

kalzumeus.com

91–100 of 119 posts

Re: What Heartbleed Can Teach The OSS Community About Marketing

#91
post #57

Earlier quoted context omitted.

How is patio11 using this "to capitalize" and "to market himself"? Anyone who follows him knows that security-related "PSAs" are a staple of his Twitter feed. Combine that with the fact that he writes about marketing on a regular basis and this post is very much par for the course. Both his PSAs and his material on marketing and business are a real service to everyone. That's why they've been so popular on HN for yea…

> Both his PSAs and his material on marketing and business are a real service to everyone. That's why they've been so popular on HN for years. HN loves startup porn, but how is this any different than how self-help books are marketed? Distrust anyone who makes a business out of telling other businesses how to be successful in business because of how they're successful in business. The people who are successful don't…

I agree with you in a general sense, but I disagree with you in this particular case.

patio11 first made a business, then did consulting, and is now building another business.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#92

Earlier quoted context omitted.

You don't think for a second that the reason you were all working so hard to fix this is entirely because of the marketing? The intense marketing of Heartbleed alerted legit crackers (who would have found out anyway), and a thousand times worse, it alerted wannabe crackers of low hanging security exploit fruit. Marketing works both ways, you know.

My apologies, I accidentally downvoted this. I strongly agree -- this should have NOT been publicly marketed in this way until vendors had some to assembly updates, and possibly not even then. Serious security vulnerabilities do their own marketing for the people that need to know about them. This is just lowering security to the tabloid level for mass consumption by users who can't fix the issue anyway.

The moment it was made public information, there was absolutely no reason whatsoever to hold back on marketing it. Even if your chosen Linux distribution isn't quite ready to go with an easy fix, by being aware of the problem you're a lot more prepared to deploy a fix the moment it becomes available.

The only people that holding back (after the vulnerability becomes public knowledge) helps are the attackers.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#93
post #46

Earlier quoted context omitted.

Wait, surely getting everyone to scramble is a good way to get the fix released soon?

Marketing is entirely the wrong way to get the people who release fixes to scramble. At least at the top few tiers (package developers and distribution maintainers) you know the organizations necessary to contact, and how to contact them. If the orgs are worth their salt, a descriptive email to their security contacts is faster and easier than a marketing campaign. Marketing is useful to get sysadmins too lazy to sub…

> Marketing is useful to get sysadmins too lazy to subscribe to security announcement mailing lists to apply the already-released patches

Which, let's be honest, is the vast majority of people who admin servers these days.

With cloud servers, VPSes, etc., anyone can become a "sysadmin," and lots of people do who don't really understand what they are signing up for. These are the people running the unpatched boxes that Ars Technica recently called "the slum houses of the Internet." (http://arstechnica.com/security/2014/03/ancient-linux-server...)

Those people aren't going to patch their system just because a CVE was issued. They don't know what a CVE is. So marketing the problem is critical to reach them and get them off their duffs.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#94
UK Offtopic: kalzumeus.com is being blocked under the category 'gambling' for me by the TalkTalk HomeSafe filter. First time I've seen the filter. My ADSL over copper connection is provided by EE.

https://dl.dropboxusercontent.com/u/8403291/talktalk-blockin...

I can't change the settings as I am not a TalkTalk customer (to my knowledge, my connection has remained functional despite mergers: Freeserve -> Wanadoo -> Orange -> EE). I certainly don't have a 10 digit customer reference and my account email is 'unknown' to the filter.

Cameron's cyber-nanny can be circumvented for eminently respectable domains such as this by judicious use of ?oo?le Cache of course.

Anyone else from the UK with default filter settings seeing this? I'm about to write to my M.P. and some wider data points would be helpful.

I have used the 'report' button: perhaps they will unblock the domain when they realise it is about Bingo.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#95
post #24

Earlier quoted context omitted.

Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. I would not be surprised if at least FB and Twitter also had early access. It was clear from the beginning that as soon as the details became public, a race would begin for the script-kiddy-friendliest tool to own sites/users. And the most likely targets of script kiddies should b…

> Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. AWS is at least as important, as is Akamai. My point being, it's not enough to hand-wave about who's the biggest and most important. A good system would give anyone with enough at risk a clear path to earn a seat at the table. Major providers could create an "early warning discl…

How do you notify a large-ish group of a secret vuln without notifying any of the bad guys?

Because if you notify the bad guys at the same time, then you've made it worse, since people you didn't notify don't know anything is up yet.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#96
post #13

Yes entirely on name, visual identity and first three paragraphs. More like this for serious vulns, please. Also, what a great name. The remaining of the page is a loud reminder of the gap between the sec and dev communities, at least as practiced in lolstartupland. Or at least between offence and defence. The second paragraph tells you the sky is falling, and then it takes them 13 questions to tell you which openssl…

But can we still have the CV numbers as well please.

"The security community refers to vulnerabilities by numbers, not names. This does have some advantages, like precision and the ability to Google them and get meaningful results all of the time"

I wish everyone embedded a Dewey Decimal number into their factual pages. Would be ace.

"I saw some kvetching on Twitter to the effect that the logo designer heard about Heartbleed before the distribution maintainers at e.g. Ubuntu and RedHat did."

Updates for Debian and CentOS landed within hours. Would have been nice to have them as we read the page.

Interestingly nothing (apparent) for Manjaro yet. Manjaro is a staged version of Arch which I have installed on a test machine to sample Gnome 3.12 when it lands in the repository a week or so.

    [keith@mocha ~]$ openssl version
    OpenSSL 1.0.1f 6 Jan 2014
Sort of ties in with

http://allanmcrae.com/2013/01/manjaro-linux-ignoring-securit...

perhaps. I get the impression that Manjaro (and other similar client OSes) are mainly for end users and not on servers.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#97
post #13

Yes entirely on name, visual identity and first three paragraphs. More like this for serious vulns, please. Also, what a great name. The remaining of the page is a loud reminder of the gap between the sec and dev communities, at least as practiced in lolstartupland. Or at least between offence and defence. The second paragraph tells you the sky is falling, and then it takes them 13 questions to tell you which openssl…

There is no doubt that masterful branding of the bug helped with patching of vulnerable systems in this case. It is not at all clear that the trend it will surely start will be a good thing. Marketing does improve visibility. But it also, inherently obscures the truth. Even in this case: some people on HN don't know that it was a Google researcher who first discovered/reported the bug; the actionable/technical information on the bug was hidden below the fold because the primary goal of the page was to be a long term marketing tool for the security firms, not the shortest path to patch vulnerable systems. We will see how this trend develops but I would not be surprised if we get more and more marketing with less upside (necessary visibility) and more downsides.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#98
post #36
post #23

Earlier quoted context omitted.

And what about Google? and Amazon? And banks? And .gov sites? I'm not sure how you can handle this in any different way as they did, really.

Google was one of the discoverers. From the page: ...independently discovered by a team of security engineers (Riku, Antti and Matti) at Codenomicon and Neel Mehta of Google Security

Would be interesting to know if the production people at Google rolled out a fix before general announcement. E.G. is internal communication in such a large organisation still faster than intertube?

Re: What Heartbleed Can Teach The OSS Community About Marketing

#99
post #33

I'm noticing this at work, too. Give things - even entire contexts - short, pronouncible names. For example, at our place, "Munin" or recently "Graphite" have been established as the name for our monitoring systems. They describe a system spanning a couple hundreds servers, include a handful of different daemons and configurations and generally, a lot that's going on, so the term is inherently ambiguous and imprecise…

I read that as Moomin at first.

As a teacher, I give silly names to maths topics and it seems to help the students organise their 'big picture' a bit.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#100

Earlier quoted context omitted.

Oh, great. Then in a few years we can have minor security issues given names, too. Like how winter storms this past winter were called "Polar Vortexes." This world needs less media sensationalism, not more.

They can just use NSA-style semi-random codenames. Every CVE can be automatically assigned a pair of words out of a hat. It'll be particularly beautiful when combined with already-silly software names. I want to have to tell my boss that Raring Ringtail has been affected by Nevada Horseshoe or somesuch.

Please don't joke about this kind of stuff.

MOODLE is an eminently useful free software course management system. A PHB I used to work for got very worried about the 'silly name' and the lack of an 0845 number for when anything went wrong. Took ages to convince him that it was a sensible alternative to another well known course management system that cost a couple of teacher salaries per year.

We got there.

Post reply on HN