Live data from Hacker News

IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

samsclass.info

1–10 of 54 posts

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#2
Disclosure to Apple - Apple notified 12-11-12.

I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week."

I wonder if it is out of concern they will be pressured to keep quiet?

There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, because, more often then not, the security researcher faces the risk of legal action and being shut down.

That pattern, though, "We are going to announce a security hole in major vendor product" followed by, "Shut down by legal action" - happens so frequently that I often wonder whether that's actually part of some larger pattern of entrepreneurial behavior that's opaque to me, it happens so frequently. Maybe it enhances your reputation? Gets you in the news?

I'm all for full disclosure, but, it might be nice to give the vendor a week to have a patch that can roll out at the same time as you let the world know what you found.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#3
Reminds me of the '90s when WinNuke and Smurf attacks ran wild. Remember one attack that caused our Linux boxes to panic, but I can't remember what it was called. It's not surprising that we're seeing stuff like this in v6. IPv4 has had the bugs hammered out from years of attacks, v6 not so much.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#5

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

http://blogs.computerworld.com/mac_os_x_java_fiasco_apple_st...

http://www.the4cast.com/apple/apples-flashback-fiasco-what-r...

2 years apart, same outcome. Apple has a terrible track record of fixing bugs. As of so far it seems giving them a minute, week, or month has no difference. In the past other vendors have had issues with timely fixing their bugs or trying to squash disclosers, that's why lists like full disclosure exist to this day.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#6
post #3

Reminds me of the '90s when WinNuke and Smurf attacks ran wild. Remember one attack that caused our Linux boxes to panic, but I can't remember what it was called. It's not surprising that we're seeing stuff like this in v6. IPv4 has had the bugs hammered out from years of attacks, v6 not so much.

Ping of Death: http://insecure.org/sploits/ping-o-death.html

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#8
post #5

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

http://blogs.computerworld.com/mac_os_x_java_fiasco_apple_st... http://www.the4cast.com/apple/apples-flashback-fiasco-what-r... 2 years apart, same outcome. Apple has a terrible track record of fixing bugs. As of so far it seems giving them a minute, week, or month has no difference. In the past other vendors have had issues with timely fixing their bugs or trying to squash disclosers, that's why lists like full disc…

We should find a better example - both of yours were Java Vulnerabilities. I totally agree that Apple needs to fix these if they are going to Ship Java with their product, but, their ability to quickly roll out a Java patch is somewhat less than their ability to quickly tweak the ICMP6 handling stack of their OS.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#9

Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…

There is an active debate on whether immediate full disclosure is the right or the wrong response. In general until there is public disclosure, vendors do not feel motivated to fix problems. Unless you release details, people cannot verify that they are vulnerable. And if an exploit is already circulating among "the bad guys", then you're not doing that much damage by disclosing.

In this case it looks like someone is publicly disclosing a vulnerability that is already in circulation, and presumably is in use somewhere. A vulnerability which might have the potential for remote code exploits against multiple operating systems, and there is no guarantee that someone hasn't figured that out and is using it right now. For someone squarely on the full disclosure side of the debate, this would be about the best case to fully disclose everything, immediately.

Post reply on HN