Live data from Hacker News

IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

samsclass.info

51–54 of 54 posts

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#51
post #49
post #31

Earlier quoted context omitted.

When I say "in general" that means not so for every vendor. That said, Apple's track record on this topic is not exactly stellar.

Apple rolls out security updates infrequently, but it seems that every time they do, I see fixes for issues I'd never heard of before. Now, I don't exactly seek out vulnerability reports, but they certainly seem to be fixing things that didn't get high-profile articles on social news sites.

This is true.

But people who submit security issues to them say that their turnaround time tends to be very long. Which is bad for their customers if the submitted security issue is being exploited in the wild.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#52
post #43

Earlier quoted context omitted.

Sometimes I'm really baffled by the dominance of American date formats instead of clear, natural and sortable ISO 8601. YYYY-MM-DD HH:MM:SS.ffffff+ZZZZ

I used to think the same way until I moved to the UK and people expressed the opinion that YYYY-MM-DD is still an American format. I guess because for them the day always comes before month. Nevertheless, ISO 8601 is clearly the ideal format for its sortability and consistency, cultural imperialism be damned!

Heh. At a previous job I advocated that format so much that people thought it was a Canadian format.

They were quite surprised when I told them the actual format that was used in Canada.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#53
post #43

Earlier quoted context omitted.

Sometimes I'm really baffled by the dominance of American date formats instead of clear, natural and sortable ISO 8601. YYYY-MM-DD HH:MM:SS.ffffff+ZZZZ

I used to think the same way until I moved to the UK and people expressed the opinion that YYYY-MM-DD is still an American format. I guess because for them the day always comes before month. Nevertheless, ISO 8601 is clearly the ideal format for its sortability and consistency, cultural imperialism be damned!

For anything handwritten (cheques, dates on signatures etc.), I use YYYY-Mmm-DD (e.g. 2012-Jan-10), as I can't imagine anyone confusing the meaning of it. I avoid DD-MM-YYYY and MM-DD-YYYY, as I usually end up having to check what I meant. No one has commented on it yet.

Typed, I use YYYY-MM-DD (e.g. 2012-01-10), mainly for its sortability.

Re: IPv6 Attack Kills Mac OS X and makes Windows Server 2012 restart in Seconds

#54
post #39
post #24

Earlier quoted context omitted.

Unless there were an easy workaround which you could disclose only with disclosing the rest of the problem - yes, it was.

This assumes something that I don't believe is defendable: that bad people wanting to install keyloggers on these systems did not already have knowledge of this vulnerability (or, even simpler, that one would seriously believe that they would be unable to find this vulnerability without splicer having told them about it, as somehow he had unique knowledge of the system). Just because I don't have a way to protect mys…

It does not matter - 99.99% of the users have no means or expertise to detect or disable a keylogger if somebody installed it. Unless there is a tool that would allow them do do it, disclosing the vulnerability is useless for them. On the other hand, if such tool exists, it can probably be published without full disclosure. You are not better of not knowing, you are the same (unless you are in highly qualified 0.01%), however various criminals - who do not have time/expertise to find vulnerability themselves, but can exploit known ones - immediately gain edge over you once it is published. For example, I myself, without knowing existing vulnerabilities, probably could not in reasonable time find one, but given a good disclosure of one, I probably could, using existing tools and with some luck, produce a working exploit for many of existing types of holes.

So the problem is that irresponsible disclosure does not help victims at all, and does help criminals. The only positive thing in irresponsible disclosure is that if vendor is unreasonably slow with issuing patches, and exploits are already known to be in the wild, then the harm is minimal, and disclosure can raise the priority of the fix. But absent this knowledge, responsible disclosure is almost always better for the users.

Post reply on HN