Live data from Hacker News

Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

modzero.com

141–150 of 167 posts

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#141

Earlier quoted context omitted.

The example I generally use is when Peter Bright went on a several month set of tirades while a staff writer for arstechnica lambasting project zero disclosing a microsoft vulnerability after the disclosure window was up. Hard to find the source though now that his articles have been scrubbed ever since he got caught trying to diddle some children. : \ In the comments, most of the devops/sysadmin community of arstech…

I don't much care what Peter Bright thinks or said a decade ago. Peter Bright isn't a security researcher, or on a vendor security team. He's just some guy (or, was some guy) on Twitter. Project Zero, meanwhile, is the global gold standard for coordinated vulnerability disclosure. Lots of people with better reputations than Bright have publicly lobbied against disclosure of any sort. Bruce Schneier is a great example…

He was one of the most important tech journalists in the world when he was saying this stuff; his fame came before his twitter account. He was also functionally a mouthpiece for Microsoft PR, available to run hit pieces on situations that were otherwise embarrassing for Microsoft.

And project zero puts an emphasis on disclosure, not coordination. When the ticker runs out they nearly always disclose, regardless of where coordination is at. That's what Peter Bright was ultimately complaining about; they disclosed like a week before one of the relevant patch tuesdays.

Like I've said, the primary point isn't the coordination. That's the carrot to get the vendors to play game on a sane schedule because otherwise the vendor holds all the cards.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#142
post #96

Earlier quoted context omitted.

> Bug disclosure without a known remedy has to be an absolute last resort kind of thing, and it's actually a little upsetting that modzero used that tactic as a kind of threat I don't think it is upsetting at all. "We found a vulnerability" "There's no vulnerability" "No, you misunderstand, here's how it works and how to exploit" "Naah, no vulnerability" "Ok, if there's no vulnerability as you claim, you don't mind u…

The thing is, "releasing our findings to the public" puts the vendor's customers at risk, it's not just some imagined Just Punishment For The Guilty, innocents get hurt. Imagine if you took a new job and they had a bunch of hardware sitting around from such a vendor. Would you be OK if someone published an exploit for your systems? (In this case, the vulnerability seems minor, so it's sort of academic. But I'm not un…

The vendor's customers are already at risk. It's a peculiar arrogance to imagine otherwise.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#143

Earlier quoted context omitted.

A bit speculative, but the word "NDA" appears four times in their post.

Yea I noticed that, but what do they specifically not like about the NDA? afaik, HackerOne still makes vulnerability disclosure possible (and automatic if taking too long?)

There have been claims that companies are abusing the HackerOne NDA process to cover up security issues: refuse to acknowledge a problem, but weild the NDA to prevent disclosure of the supposed non-existent disclosure.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#144

Earlier quoted context omitted.

I don't much care what Peter Bright thinks or said a decade ago. Peter Bright isn't a security researcher, or on a vendor security team. He's just some guy (or, was some guy) on Twitter. Project Zero, meanwhile, is the global gold standard for coordinated vulnerability disclosure. Lots of people with better reputations than Bright have publicly lobbied against disclosure of any sort. Bruce Schneier is a great example…

He was one of the most important tech journalists in the world when he was saying this stuff; his fame came before his twitter account. He was also functionally a mouthpiece for Microsoft PR, available to run hit pieces on situations that were otherwise embarrassing for Microsoft. And project zero puts an emphasis on disclosure, not coordination. When the ticker runs out they nearly always disclose, regardless of whe…

I simply don't care what Peter Bright says, and neither does anybody else in the field. We're now arguing for the sake of arguing. It's plainly correct that the term "Responsible Disclosure" is disfavored, and disfavored for the reasons I say it is. I didn't come up with any of these things; I just work in vulnerability research (or used to) and know what the stories are.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#145

Earlier quoted context omitted.

> No, I was there at the inception of this term, and it was absolutely originally imagined as a way of controlling researchers and giving vendors more power over information about their products. I mean, that half is the carrot to get vendors to play ball and actually fix their shitty code occasionally. It lets unaffiliated white hat security researchers who are just trying to get sec issues fixed actually get some f…

As Google proved long ago, the only thing you have to do to get vendors to fix their shitty code is to set a fixed timeline for disclosure; just tell the vendor "please let us know when this is patched, and we're disclosing regardless after 60 days". The point of calling it "responsible" has nothing to do with defending researchers; it's literally the opposite. The norms of "responsible" disclosure were absolutely no…

The use of 'responsible' wrt vulnerability disclosure is thought to at least go back to 2001's essay "It’s Time to End Information Anarchy", and I know that the adjective 'responsible' was being thrown around wrt vulnarability disclosure before that. @stake did not invent the term in the early aughts. https://web.archive.org/web/20011109045330if_/http://www.mic...

Yes, CERT has moved using CVD, but I argue that's because of their conservationism. They don't want to rock the boat and tend towards vendor friendly, neutral language. That makes sense for their niche.

And just throwing it out there that the older term that's actively being erased because its implications are unfriendly to entrenched interests isn't the "Orwellian" one.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#147

Earlier quoted context omitted.

As Google proved long ago, the only thing you have to do to get vendors to fix their shitty code is to set a fixed timeline for disclosure; just tell the vendor "please let us know when this is patched, and we're disclosing regardless after 60 days". The point of calling it "responsible" has nothing to do with defending researchers; it's literally the opposite. The norms of "responsible" disclosure were absolutely no…

The use of 'responsible' wrt vulnerability disclosure is thought to at least go back to 2001's essay "It’s Time to End Information Anarchy", and I know that the adjective 'responsible' was being thrown around wrt vulnarability disclosure before that. @stake did not invent the term in the early aughts. https://web.archive.org/web/20011109045330if_/http://www.mic... Yes, CERT has moved using CVD, but I argue that's bec…

I'm sorry, but I think you're just kind of making things up here to perpetuate an unproductive argument. By "conservative", I meant that CERT is broadly anti-disclosure in all forms, which I think is a claim that pretty much anyone working in vulnerability research would recognize.

Here's the 2002 I-D that Weld worked on with Steve Christey standardizing the term. It's notable for being roughly contemporaneous with @stake firing Dan Geer over, as I recall, somehow alienating Microsoft, one of @stake's larger clients.

https://cve.mitre.org/data/board/archives/2002-02/msg00026.h...

Your link, for what it's worth, doesn't use the term at all. But even if it had, it wouldn't change anything.

Just to keep this on track: your claim was that "Coordinated Disclosure" --- the near-universal standard term for what used to be called "Responsible Disclosure" --- is an "Orwellian re-imagining". Leaving aside the fact that there's nothing intrinsically "Orwellian" about renaming something, the fact remains: "Responsible Disclosure" was researcher-hostile and patronizing, and has been chucked out the window by almost everybody who matters in vulnerability research.

We've managed to hash out a hot topic from, like, 2012 on this thread, which is great, it's progress, we move forward bit by bit here on HN, just like Joel Spolsky once said; "fire and motion". But we can probably be done now.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#148
post #133

Earlier quoted context omitted.

Seriously. I don't think the researcher realizes how many people try to bypass hackerone because H1 would have flagged their finding as invalid. Using h1 isn't about bug bounties, it's about not having to spend a 1-2 of your team's full time engineers triaging security researcher reports.

We had some of the dumbest H1 "findings" at some companies that I worked: - Service that is explicitly out of scope of program is "leaking" default CloudFront headers. - Android application can be decompiled (that's it, not secret is there, just the fact that it's possible) - "I can do something bad IF I had a way to load malicious JavaScript" (no, CSRF protection was one and correctly implemented) (there is also no…

This has been my experience, too, with security reports in general. We see things like:

- "An attacker could spoof an email from you to a user." (POC video shows Yahoo webmail succeeding. We try the same thing in Gmail, and it gets sent to the spam folder because it fails SPF and DKIM.)

- "If I try logging in as a user with an invalid email too many times, it locks them out of their account. That's a denial of service." (Well, yeah, and that's a bummer, but it beats allowing an attacker unlimited attempts.)

I'll say, though, that H1 has been super helpful at screening the worse reports. Sometimes they'll initially block reports like the above, but the researcher will insist that this time it's for real. I don't feel too bad closing those reports as invalid.

In all, I'm a very happy H1 customer. They've been good to work with.

Re: Ridiculous vulnerability disclosure process with CrowdStrike Falcon Sensor

#150

I hate that the component the vulnerability was in even exists. As far as I'm concerned, if a program tries to keep a local administrator from uninstalling it, for any reason , it's malware.

Sorry, but I disagree. You have to look at the customer base crowdstrike is serving which can be wide and varied. There exist environments where the user "needs" admin privileges but should not be able to uninstall the sensor. Think corp where users code etc, but they dont have the admin staff to do some more complicated IT security. In that instance this is just what is needed. Also, privilege escalation exist and these sensor server to help prevent do IR for real malware.
Post reply on HN