Earlier quoted context omitted.
Actually, the world _does_ stop turning because it's Sunday. Anything happening on the weekend is emergency management, which takes time to scramble. I work in network/information security, and if we had a security incident on a Sunday, it would go to our backup team (of one). If they (he) deemed it critical, they would notify the security director, who would notify my boss, who would notify the rest of the team. Thi…
I agree. But we're talking about software as a service here, and that kinda makes it a different ballgame. Folks are paying money (in some cases) to use your software living on your servers (or, at least servers that you manage). I would certainly hope that someone who can deal with outages or penetrations is actually working on the weekend (perhaps that person doesn't work Monday and Tuesday?). Would you say "eh, bu…
Responsible Disclosure Policy
71–80 of 85 posts
Re: Responsible Disclosure Policy
#72What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…
Re: Responsible Disclosure Policy
#73Earlier quoted context omitted.
Actually, the world _does_ stop turning because it's Sunday. Anything happening on the weekend is emergency management, which takes time to scramble. I work in network/information security, and if we had a security incident on a Sunday, it would go to our backup team (of one). If they (he) deemed it critical, they would notify the security director, who would notify my boss, who would notify the rest of the team. Thi…
> Actually, the world _does_ stop turning because it's Sunday. Incorrect. In Islamic countries, which are a part of this world, like Saudi Arabia and Oman have Thu-Fri weekend. http://en.wikipedia.org/wiki/Workweek_and_weekend#Islamic_co...
Re: Responsible Disclosure Policy
#74The thing I haven't heard a straight answer on is 1) how long has the bug existed, 2) have they proved that it wasn't previously exploited.
Re: Responsible Disclosure Policy
#75What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…
That's not what "black-hat" means.
Re: Responsible Disclosure Policy
#76I hate to be the one pointing out this but it's a shame that a company like GitHub will reward responsible disclosures just with a thank you and the promise to not pursue a legal action. http://help.github.com/responsible-disclosure/ "white hat researchers are always appreciated"
Re: Responsible Disclosure Policy
#77Earlier quoted context omitted.
If what you're implying here is that they should be offering a bounty for discovery of bugs, I'm not necessarily disagreeing with you, but to expect them to get a policy about that and to allocate funding for those bounties on a Sunday, within 24 hours of a major, public breach seems a little unreasonable.
I'm with you but still it's silly they didn't have a responsible disclosure program until today in the first place.
Re: Responsible Disclosure Policy
#78What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…
The vulnerability was public, known for years, and no doubt already exploited. Making a splash about it on GitHub, popular as it is with rails hackers, is the best thing that could happen to the security of the rails ecosystem.
Re: Responsible Disclosure Policy
#79What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…
>the compromise of an account not held by him puts him clearly into the "black-hat" category. That's not what "black-hat" means.
Gain unauthorized access to an account and using it falls under pretty much any standard definition of "black-hat" and in practical terms breaks computer security laws in pretty much all legal jurisdictions which have them.
Re: Responsible Disclosure Policy
#80What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…
>the compromise of an account not held by him puts him clearly into the "black-hat" category. That's not what "black-hat" means.