Live data from Hacker News

What Heartbleed Can Teach The OSS Community About Marketing

kalzumeus.com

111–119 of 119 posts

Re: What Heartbleed Can Teach The OSS Community About Marketing

#111
post #92

Earlier quoted context omitted.

My apologies, I accidentally downvoted this. I strongly agree -- this should have NOT been publicly marketed in this way until vendors had some to assembly updates, and possibly not even then. Serious security vulnerabilities do their own marketing for the people that need to know about them. This is just lowering security to the tabloid level for mass consumption by users who can't fix the issue anyway.

The moment it was made public information, there was absolutely no reason whatsoever to hold back on marketing it. Even if your chosen Linux distribution isn't quite ready to go with an easy fix, by being aware of the problem you're a lot more prepared to deploy a fix the moment it becomes available. The only people that holding back (after the vulnerability becomes public knowledge) helps are the attackers.

> The moment it was made public information, there was absolutely no reason whatsoever to hold back on marketing it.

There's a lot of different kinds of public. "Possibly in the wild" is very different than "available to every script kiddie under the sun".

Re: What Heartbleed Can Teach The OSS Community About Marketing

#112

Earlier quoted context omitted.

> Both his PSAs and his material on marketing and business are a real service to everyone. That's why they've been so popular on HN for years. HN loves startup porn, but how is this any different than how self-help books are marketed? Distrust anyone who makes a business out of telling other businesses how to be successful in business because of how they're successful in business. The people who are successful don't…

I agree with you in a general sense, but I disagree with you in this particular case. patio11 first made a business, then did consulting, and is now building another business.

Bingo Card Creator. Let's just keep the scale in mind here.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#113
post #97
post #13

Yes entirely on name, visual identity and first three paragraphs. More like this for serious vulns, please. Also, what a great name. The remaining of the page is a loud reminder of the gap between the sec and dev communities, at least as practiced in lolstartupland. Or at least between offence and defence. The second paragraph tells you the sky is falling, and then it takes them 13 questions to tell you which openssl…

There is no doubt that masterful branding of the bug helped with patching of vulnerable systems in this case . It is not at all clear that the trend it will surely start will be a good thing. Marketing does improve visibility. But it also, inherently obscures the truth. Even in this case: some people on HN don't know that it was a Google researcher who first discovered/reported the bug; the actionable/technical infor…

I seriously wished they had something like:

Step 1: Run this command. If it returns "Your vulnerable!" go to step 2.

And so on, with actionable steps that people could quickly understand and circulate.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#114
post #68

Earlier quoted context omitted.

Whew. Good thing I don't run such a service. :-) (Edited my comment to better emphasize that it was hypothetical.)

I knew it was hypothetical, I was just building off my experience with this as a reality and not a thought experiment. I think that your hypothetical is useless to this conversation. The seriousness of death is a good argument tool, but using it in the context of responsible disclosure is theatrics. Arguing for people with privileged access to the exploit to behave the way you want when disclosing it, is a lot like a…

Yup. It's a great point. I do frequently mention the safety aspect in conversations about secure channels because I know that was how the importance of the work was pitched to me when I worked with a VPN provider in the past. (As a developer, but not in a role where I would have anything to do with the FMEA you mentioned. I had to look that acronym up.) I think it's a good point for people to keep in mind.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#115
post #13

Yes entirely on name, visual identity and first three paragraphs. More like this for serious vulns, please. Also, what a great name. The remaining of the page is a loud reminder of the gap between the sec and dev communities, at least as practiced in lolstartupland. Or at least between offence and defence. The second paragraph tells you the sky is falling, and then it takes them 13 questions to tell you which openssl…

Heartbleed is not super descriptive to layfolk but it's certainly catchy, I'll give you that. Having a dot-com domain with said simple name was great, too.

But the content? A loud reminder indeed. As a member of the dev community, I would have wanted to see the following:

1. How bad is it? If you're using SSL, then an attacker may be able to read your machine's memory without leaving a trace.

2. Who is affected? Users of OpenSSL versions X-Y. Check your site here [http://filippo.io/Heartbleed/], but your client code may be affected too!

3. How do I secure myself? Update to OpenSSL version Z, reboot, and consider resetting all sensitive data on your server (reissue your SSL certificate, reset your user passwords and sessions, etc).

These facts are littered throughout a 2,000+ word document. In the future, I would like to see these things answered plainly at the very top.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#116
post #24

Earlier quoted context omitted.

> Because Cloudflare is possibly the biggest and most vulnerable target due to the enormous number of websites and businesses relying on it. AWS is at least as important, as is Akamai. My point being, it's not enough to hand-wave about who's the biggest and most important. A good system would give anyone with enough at risk a clear path to earn a seat at the table. Major providers could create an "early warning discl…

Software security used to work this way, in the early 90s. Disclosures went to vendor cabals. They leaked like sieves and were a running joke on #hack. It's hard to argue: yes, the world would be better if only the people who were going to mitigate the bug had the information until everyone had mitigated. But a repeal of the CAP theorem would be nice too. Meanwhile, we have to work with the world we have, not the one…

It still obviously does work this way, just very informally. That is, such cabals clearly exist and clearly get early access. If things seem different now, perhaps it's because the timelines are shorter or the cabals more consolidated.

As for "most clueful": I have often lamented the current pendulum swing toward a centralized internet. But this is one area where all the centralization of infrastructure has a benefit. An awfully large fraction of the internet's data is in the hands of a small number of relatively tech-clueful organizations.

How many of Heroku's or AWS's or Akamai's customers would still be unpatched right now if those customers were managing things themselves? I'd put any of those organizations safely ahead of their median customer in the "clue" department.

I'm not going to disagree with your main point though: funding for security is always an uphill battle. When it's working great, nothing happens.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#117
Should we really be branding vulnerabilities? I found this to be very odd.

First of all its a bit inflammatory even for a severe vulnerability. Even if the entire internet ONLY used openSSL (which it doesnt), it only affected one version which most people are not on.

Second, its misleading to think that because bug is "branded", that it wont be forgotten about it surely will be like every other CVE out there. We can all post rants til we are blue in the face, unless there is automated testing for its presence (or you perfectly manage all your internal dependencies), this bug (on the large) will probably never go away 100%.

Third, if not for Snowden, nobody would even be talking about this.

Re: What Heartbleed Can Teach The OSS Community About Marketing

#118
post #13

Yes entirely on name, visual identity and first three paragraphs. More like this for serious vulns, please. Also, what a great name. The remaining of the page is a loud reminder of the gap between the sec and dev communities, at least as practiced in lolstartupland. Or at least between offence and defence. The second paragraph tells you the sky is falling, and then it takes them 13 questions to tell you which openssl…

But can we still have the CV numbers as well please. "The security community refers to vulnerabilities by numbers, not names. This does have some advantages, like precision and the ability to Google them and get meaningful results all of the time" I wish everyone embedded a Dewey Decimal number into their factual pages. Would be ace. "I saw some kvetching on Twitter to the effect that the logo designer heard about He…

Replying to my own comment as edit time has passed.

Manjaro: update arrived this morning, may have been available for past 12 hours, so promoted through the 'staging' cycle. Half a day to a day later than Ubuntu/Debian/Redhat if I have my times correct.

    [keith@mocha ~]$ openssl version
    OpenSSL 1.0.1g 7 Apr 2014

Re: What Heartbleed Can Teach The OSS Community About Marketing

#119

Earlier quoted context omitted.

I agree with you in a general sense, but I disagree with you in this particular case. patio11 first made a business, then did consulting, and is now building another business.

Bingo Card Creator. Let's just keep the scale in mind here.

Bingo Card Creator and Appointment Reminder. The latter is big enough he's started doing angel investing. Keep in mind, he runs both of them by himself and he no longer consults. I'm not saying he doesn't have an ulterior motive, but his motives are considerably more pure than 99% of the articles on hacker news.

Not that it matters. Who cares where the advice comes from if it works? And if it doesn't work, the purest motives in the world isn't going to make it work.

Post reply on HN