IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
21–30 of 54 posts
Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
#22Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…
There is an active debate on whether immediate full disclosure is the right or the wrong response. In general until there is public disclosure, vendors do not feel motivated to fix problems. Unless you release details, people cannot verify that they are vulnerable. And if an exploit is already circulating among "the bad guys", then you're not doing that much damage by disclosing. In this case it looks like someone is…
Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
#23Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…
I'm not defending the disclosure procedures but I think the author is under the impression that Apple is not going to care/respond and therefore not worth waiting X days before announcing publicly: "The new version of the attack is powerful enough that I decided to formally notify Apple. I don't expect them to care much--Microsoft certainly didn't think this was important to them, and Windows is much more vulnerable.…
Anyone want to perform a test with me?
Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
#24Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…
When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.
Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
#25http://en.wikipedia.org/wiki/Denial-of-service_attack#Teardr...
Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
#26Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…
When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.
Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
#27Reminds me of the '90s when WinNuke and Smurf attacks ran wild. Remember one attack that caused our Linux boxes to panic, but I can't remember what it was called. It's not surprising that we're seeing stuff like this in v6. IPv4 has had the bugs hammered out from years of attacks, v6 not so much.
Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
#28Disclosure to Apple - Apple notified 12-11-12. I often wonder why disclosures of these types of exploits is now, "same day" instead of "Let vendor know you will be reporting this to public in a week." I wonder if it is out of concern they will be pressured to keep quiet? There is a good practical reason for not providing advance disclosure at major conference, particularly if you're subject to some kind of NDA, becau…
I also think that a good compromise would be to pass on the exploit information to some 3rd party, tasked with releasing full details at a certain date (or simply, the responsible release of the exploit). The focus of pressure would then shift from the researcher to this 3rd party, which would presumably have the means to resist the pressure.
Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
#29Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds
#30Earlier quoted context omitted.
When I discovered a vulnerability in Mac OS X that would allow a unprivileged user to keylog every user on the system (CVE-2007-0724), I let Apple know, then kept quiet until they fixed the issue. It took them 11 and a half months to fix. They thanked me in the security update note, and I now how a CVE on my resume. Was silence the most morally correct action? To this day, I am still unsure.
I've never thought to put CVE-IDs I'm credited for reporting on my resume. Is that...a thing? Do tech employers (outside of security consultancies) even know what a CVE-ID is?