Live data from Hacker News

What Heartbleed Can Teach The OSS Community About Marketing

kalzumeus.com

101–110 of 119 posts

Re: What Heartbleed Can Teach The OSS Community About Marketing

#101
post #24

Earlier quoted context omitted.

Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. I would not be surprised if at least FB and Twitter also had early access. It was clear from the beginning that as soon as the details became public, a race would begin for the script-kiddy-friendliest tool to own sites/users. And the most likely targets of script kiddies should b…

> Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. AWS is at least as important, as is Akamai. My point being, it's not enough to hand-wave about who's the biggest and most important. A good system would give anyone with enough at risk a clear path to earn a seat at the table. Major providers could create an "early warning discl…

Software security used to work this way, in the early 90s. Disclosures went to vendor cabals. They leaked like sieves and were a running joke on #hack.

It's hard to argue: yes, the world would be better if only the people who were going to mitigate the bug had the information until everyone had mitigated. But a repeal of the CAP theorem would be nice too. Meanwhile, we have to work with the world we have, not the one we want.

Early disclosure club isn't a terrible idea, but good luck getting it funded in a serious way. The correlation between "most impacted" and "most clueful" isn't particularly strong.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#102
post #13

Yes entirely on name, visual identity and first three paragraphs. More like this for serious vulns, please. Also, what a great name. The remaining of the page is a loud reminder of the gap between the sec and dev communities, at least as practiced in lolstartupland. Or at least between offence and defence. The second paragraph tells you the sky is falling, and then it takes them 13 questions to tell you which openssl…

But can we still have the CV numbers as well please. "The security community refers to vulnerabilities by numbers, not names. This does have some advantages, like precision and the ability to Google them and get meaningful results all of the time" I wish everyone embedded a Dewey Decimal number into their factual pages. Would be ace. "I saw some kvetching on Twitter to the effect that the logo designer heard about He…

The CV number is on http://heartbleed.com/

CVE-2014-0160 is the official reference to this bug. CVE (Common Vulnerabilities and Exposures) is the Standard for Information Security Vulnerability Names maintained by MITRE. Due to co-incident discovery a duplicate CVE, CVE-2014-0346, which was assigned to us, should not be used, since others independently went public with the CVE-2014-0160 identifier.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#103
post #44

Earlier quoted context omitted.

Any result other than "the entire industry scrambling" following the public disclosure of Heartbleed would have been a failure case. How do you imagine that working out? "We need to patch millions of servers managed by hundreds of thousands of people. It all needs to happen today, and be conducted in total secrecy, because if any bad guy finds out about what we're doing there will bet net-wide exploitation by botnets…

You're demonstrating no understanding of how these things work. For updates to be deployed, the patches need to be integrated, tested, packages/updates build, and the update mechanisms tested. For complex systems -- like, say, embedded hardware -- this might involve targeting quite a few different devices and testing matrixes. Even scrambling, this can take days, and leaves users blowing in the wind in the meantime.…

This is why we have coordination with vendors PRIOR to public release, such that when the vulnerability is publicly disclosed, updates are available through standard update pipelines

Are you talking about Responsible Disclosure? Cause I thought that existed because if security researchers tell vendors in private only, then the vendors sit on it and do nothing, but if you tell the public first, users are vulnerable before the vendor releases a fix.

Isn't the only reason there's a public release as a threat to keep the vendors honest?

Re: What Heartbleed Can Teach The OSS Community About Marketing

#104
Talking about marketing: Wouldn't this be a great time for one of the not so small IT companies to pull off a publicity stunt within the tech community and donate a few full time developers to improve the openssl codebase?

For example I might not like Facebook, but if they'd actually make such a contribution to the public good I'd always have to include that counter argument in my criticism.

Maybe some one here on hackernews might be able to pull some strings?

Re: What Heartbleed Can Teach The OSS Community About Marketing

#105
post #24

Earlier quoted context omitted.

> Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. AWS is at least as important, as is Akamai. My point being, it's not enough to hand-wave about who's the biggest and most important. A good system would give anyone with enough at risk a clear path to earn a seat at the table. Major providers could create an "early warning discl…

Software security used to work this way, in the early 90s. Disclosures went to vendor cabals. They leaked like sieves and were a running joke on #hack. It's hard to argue: yes, the world would be better if only the people who were going to mitigate the bug had the information until everyone had mitigated. But a repeal of the CAP theorem would be nice too. Meanwhile, we have to work with the world we have, not the one…

Indeed, if one posits a channel for transmitting secrets among a vendor cabal which never leaks to people not authorized to receive the secrets, we should abandon SSL and use that for our secure communication needs instead.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#106

I agree with the principle; the logo even made the NYT, which had at least three stories on Heartbleed. But: are there enough two-english-word combinations left as viable .com names, much less ones that accurately describe the vulnerability?

A .bug TLD may actually work here.

Why not, we already have .coffee .florist and .dating - we should just enumerate the OED for TLDs.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#107
post #87

Earlier quoted context omitted.

He did because this is the worst internet bug in the past 10 years, not because the page was so masterfully written. Private keys and user passwords/data being disclosed will be cared about by systems administrators even without such a fancy page.

It is not the worst Internet bug in the past 10 years. It's among the most widespread Internet bugs, but: * An identical bug impacted nginx a few years ago * A far worse bug impacted Debian (when they commented out the randomness in their CSPRNG), which coughed up code execution on tens of thousands of machines; lots of companies that didn't officially deploy on Debian still had a Debian box somewhere vulnerable * Th…

This bug is on 70% of systems and ANYONE can run a python script and pull out plaintext Paypal or bank passwords. It is the worst Internet bug perhaps ever.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#108
post #12
post #8

"The Heartbleed announcement ... is masterful communication." You have to be kidding me. It took so long to decipher what I wanted to know that I went elsewhere. Edit: "masterful communication" this is not, since the reader doesn't know who the page is aimed at. Even a line at the top saying "Technical people go _here_", and then something aimed at technical people would be better.

"I know this is bad... but what exactly is broken... oh." I think this is a case where the message could have been more concise.

I agree. I saw the Heartbleed page while surfing HN, clicked through, saw something long with no TL;DR in red: THIS IS THE WORST SECURITY BUG IN MANY YEARS, AND YOUR SERVER IS VERY LIKELY AFFECTED, and ignored it for a couple of hours until I started seeing more and more posts about it.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#109
post #87

Earlier quoted context omitted.

It is not the worst Internet bug in the past 10 years. It's among the most widespread Internet bugs, but: * An identical bug impacted nginx a few years ago * A far worse bug impacted Debian (when they commented out the randomness in their CSPRNG), which coughed up code execution on tens of thousands of machines; lots of companies that didn't officially deploy on Debian still had a Debian box somewhere vulnerable * Th…

This bug is on 70% of systems and ANYONE can run a python script and pull out plaintext Paypal or bank passwords. It is the worst Internet bug perhaps ever.

I don't know a single vulnerability researcher who agrees with that statement. But you also didn't marshal any evidence; you restated the first thing I said about the bug, and then effectively said "no, you're wrong".

Re: What Heartbleed Can Teach The OSS Community About Marketing

#110
post #24

Earlier quoted context omitted.

> Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. AWS is at least as important, as is Akamai. My point being, it's not enough to hand-wave about who's the biggest and most important. A good system would give anyone with enough at risk a clear path to earn a seat at the table. Major providers could create an "early warning discl…

Software security used to work this way, in the early 90s. Disclosures went to vendor cabals. They leaked like sieves and were a running joke on #hack. It's hard to argue: yes, the world would be better if only the people who were going to mitigate the bug had the information until everyone had mitigated. But a repeal of the CAP theorem would be nice too. Meanwhile, we have to work with the world we have, not the one…

Information isn't supposed to stay in the Cabal for long. If you want 6 months (or, more typically 5 years) to fix a serious vulnerability, you shouldn't get any kind of useful protection.
Post reply on HN