Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?
Snippets from the mailing list charter[0] and listinfo[1] which simply say briefly: About Full-Disclosure Unlike bugtraq, this list serves no one except the list members themselves We don't believe in security by obscurity, and as far as we know, full disclosure is the only way to ensure that everyone, not just the insiders have access to the information we need to survive. We will try to operate this list without mo…
Full-disclosure – Administrivia: The End
41–50 of 142 posts
Re: Full-disclosure – Administrivia: The End
#42Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.
Hi, I'm posting this through Tor. The reason I'm able to do this is because this account is more than two weeks old. I also created this account through Tor, so HN's operators should have no idea who I am. For example, you have done an experiment below of posting comments through tor using the newly-created account "throughtor": https://news.ycombinator.com/threads?id=throughtor If you turn on "showdead" in your prof…
Re: Full-disclosure – Administrivia: The End
#43Earlier quoted context omitted.
Are you unfamiliar with the phrase he used, "straw that broke the camel's back"?
In this context, it's really a weasel term. He's functionally given no explanation.
In the past I've given lots of information about requests to moderate or otherwise remove content from forums I run.
Then I was hit with a cease and desist, and again provided transparency of it. The very predictable Streisand effect kicked in, and then I was hit with a harassment case too (for disclosing the details even though I knew it would likely trigger Streisand).
It was all resolved quite peacefully, but one fire-fights these things reasonably over the years and get to learn that the other party is usually not being reasonable. You can either result in escalation, or you can calm things down.
It's a lot easier to pick the option that calms things down if it's available to you. And in case above, that was apocalyptic, to close the list without disclosing detail behind it.
The last straw really breaks the camels' back. Once broken, it's not getting up to fight on. Life is too short.
Re: Full-disclosure – Administrivia: The End
#44Re: Full-disclosure – Administrivia: The End
#45Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.
Hi, I'm posting this through Tor. The reason I'm able to do this is because this account is more than two weeks old. I also created this account through Tor, so HN's operators should have no idea who I am. For example, you have done an experiment below of posting comments through tor using the newly-created account "throughtor": https://news.ycombinator.com/threads?id=throughtor If you turn on "showdead" in your prof…
Re: Full-disclosure – Administrivia: The End
#46Re: Full-disclosure – Administrivia: The End
#47Earlier quoted context omitted.
Are you unfamiliar with the phrase he used, "straw that broke the camel's back"?
In this context, it's really a weasel term. He's functionally given no explanation.
Receiving legal threats (either real of vague promises of one), being accused of censorship and denying someone's right to freedom of speech (and having to explain that's not how free speech works), cleaning up spam and trying to sort out fights between users really wears you down after a while.
A lot of work goes on behind the scenes of running a 'community' and it can be stressful, draining and generally not fun.
You are free to try to step in to the gap created by the closure of this list and run a replacement service. I'm sure someone will.
Re: Full-disclosure – Administrivia: The End
#48What a shame; I just recently started taking on an interest in computer security and signed up for the list. In just the few weeks I was on there, I learned about a vulnerability in a device I had recently bought. I am cherishing the opportunity (which I haven't found time for yet) to walk through my first exploit! As a newcomer I'm not really sure what John's referring to, though. Too bad...
One of the biggest drivers of cash into information security hires is government regulation. Otherwise, a lot of these companies could give a shit if they lose private data.
Enter the information security specialist who has no fucking clue how to program or do anything remotely technical. They went out and got their CISSP cert, and now they provide a legal shield to the corporation or government office that hires them. Their very presence provides the security theater needed to protect their employer from being sued for not providing the necessary security.
If you are a CISSP on here, the fact that you're on this site means you are in the minority of your loser poser peers. You probably hate these posers as much as I do.
Re: Full-disclosure – Administrivia: The End
#49Earlier quoted context omitted.
Snippets from the mailing list charter[0] and listinfo[1] which simply say briefly: About Full-Disclosure Unlike bugtraq, this list serves no one except the list members themselves We don't believe in security by obscurity, and as far as we know, full disclosure is the only way to ensure that everyone, not just the insiders have access to the information we need to survive. We will try to operate this list without mo…
Given the list's modus operandi and goals, wouldn't it work well under a format such as the blockchain? No moderation and no chance to delete what's been posted, since the decentralization means it would by then be replicated across lots of machines.
Re: Full-disclosure – Administrivia: The End
#50He didn't really explain the full problem so maybe I am not fully appreciating the situation here, but this seems like a pretty big overreaction for a stupid request from some a single user.
As someone who had to deal with legal troubles when running a user facing service I can say that it's not that easy if you don't have resources (or knowledge/time) to response correctly to the legal inquiries. For example, a relatively small (by internet standards) "local" forum has a somehow dedicated (it's not their full time job) 3 man legal team that answers all the legal inquiries. If I add one of the latest in…
And, the better your case, the more soul-draining it is. I would imagine that it is easy to comply when one knows he is in the wrong. But, when one feels strongly about the cause and is advised that he has an excellent case, then capitulation feels like being bullied and extorted into compromising one's principles. This, even when it is frequently the most prudent thing to do.
So, one is left with the sad choice of either compromising his principles or fighting indefinitely at significant cost in time, money, and emotional energy.