Live data from Hacker News

OS X 10.10.5 kernel local privilege escalation

github.com

141–143 of 143 posts

Re: OS X 10.10.5 kernel local privilege escalation

#141
post #140

Earlier quoted context omitted.

Technically in this case, Apple was given advance notice: https://news.ycombinator.com/item?id=10070799 . I'm guessing we'd all agree it was not a reasonable amount of time to actually fix it... but then who gets to decide what that is? If I'm counting right, it took over a month for Apple to patch DYLD_PRINT_TO_FILE, which was disclosed in a similar way. IMO's it's naive to think nobody else knew about these relativ…

You keep saying things like 'who is to decide?'. If you really believed that, you would cease posting your opinions here. The point about people not wanting to wait for Apple is valid in that certain people can protect themselves ahead of apple distributing a fix. However it clearly doesn't change the calculus since the number of people who can protect themselves is miniscule compared to the number of people made vul…

When I say "who is to decide?", I mean, as we have discussed, there is no way to be absolutely sure of the best course given the unknowns, so that reasonable people can differ, and they will, based on differing ideologies on things like risk management, duties to the public, and personal agency.

As for controversy, maybe I overstated that, but your flat counterstatement with no elaboration or support isn't going to change anyone's mind.

Re: OS X 10.10.5 kernel local privilege escalation

#142
post #140

Earlier quoted context omitted.

You keep saying things like 'who is to decide?'. If you really believed that, you would cease posting your opinions here. The point about people not wanting to wait for Apple is valid in that certain people can protect themselves ahead of apple distributing a fix. However it clearly doesn't change the calculus since the number of people who can protect themselves is miniscule compared to the number of people made vul…

When I say "who is to decide?", I mean, as we have discussed, there is no way to be absolutely sure of the best course given the unknowns, so that reasonable people can differ, and they will, based on differing ideologies on things like risk management, duties to the public, and personal agency. As for controversy, maybe I overstated that, but your flat counterstatement with no elaboration or support isn't going to c…

You keep saying 'there is no way to be the absolutely sure' - but this is a truism that applies to all of human decision making.

You are using it to make the situation seem less clear than it is rather than responding to a clearly articulated critique of your position.

If you differ on any of these topics why not say what you believe?

Re: OS X 10.10.5 kernel local privilege escalation

#143
post #142

Earlier quoted context omitted.

When I say "who is to decide?", I mean, as we have discussed, there is no way to be absolutely sure of the best course given the unknowns, so that reasonable people can differ, and they will, based on differing ideologies on things like risk management, duties to the public, and personal agency. As for controversy, maybe I overstated that, but your flat counterstatement with no elaboration or support isn't going to c…

You keep saying 'there is no way to be the absolutely sure' - but this is a truism that applies to all of human decision making. You are using it to make the situation seem less clear than it is rather than responding to a clearly articulated critique of your position. If you differ on any of these topics why not say what you believe?

It does apply to all of human decision making, which is why we have different political parties, different schools of thought within a scientific field, different types of government etc. My point is that full disclosure vs. secrecy (and various points inbetween) is an instance of that type of dilemma, so that only a closed-minded person would insist their particular choice is the only position that is always right.

As an example of how "responsible disclosure" can fail, read https://en.wikipedia.org/wiki/Shellshock_(software_bug) . It was embargoed until a patch was ready, but the patch itself invited exploitation attempts and further scrutiny which revealed additional vulnerabilities. It was quite a mess, but IMO the only "best practices"-based way to avoid it would have been to never have introduced the vulnerability in the first place. Elsewhere in this thread, I cited an instance of Apple taking three years to fix a vulnerability responsibly disclosed. Would you say it was better to let that vulnerability sit for three years than to disclose it immediately so that it would get fixed within a few months? Obviously none of this proves we should jump to instant full disclosure, I just mean the existing approaches all have issues, so there is room for personal opinion and judgment. I don't even feel strongly about second-guessing this particular instance, because I'm betting the discloser knows more than we do. (And if you don't trust him, refer to my previous comments -- why trust Apple, when they have a record of being fairly slow?)

If I'm obfuscating by saying we can't know, you're making it deceptively simple by claiming you do know with broad statements like "the number of people who can protect themselves is miniscule compared to the number of people made vulnerable" (even though I've argued third parties can help secure unknowledgable users, if the issue is publicly disclosed before an Apple patch), "It's a matter of statistics", "the fact that the vulnerability wasn't publicly known" (how do you define "public" in a way that is both meaningful to your position and can be exhaustively searched to prove the "fact" that this wasn't known?).

Post reply on HN