Live data from Hacker News

Responsible Disclosure Policy

github.com

71–80 of 85 posts

Re: Responsible Disclosure Policy

#71
post #41

Earlier quoted context omitted.

Actually, the world _does_ stop turning because it's Sunday. Anything happening on the weekend is emergency management, which takes time to scramble. I work in network/information security, and if we had a security incident on a Sunday, it would go to our backup team (of one). If they (he) deemed it critical, they would notify the security director, who would notify my boss, who would notify the rest of the team. Thi…

I agree. But we're talking about software as a service here, and that kinda makes it a different ballgame. Folks are paying money (in some cases) to use your software living on your servers (or, at least servers that you manage). I would certainly hope that someone who can deal with outages or penetrations is actually working on the weekend (perhaps that person doesn't work Monday and Tuesday?). Would you say "eh, bu…

No, it would still be an emergency, but the response time (unless guaranteed by a SLA) would likely vary. Does GitHub have a SLA?

Re: Responsible Disclosure Policy

#72
post #70

What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…

The vulnerability was public, known for years, and no doubt already exploited. Making a splash about it on GitHub, popular as it is with rails hackers, is the best thing that could happen to the security of the rails ecosystem.

Re: Responsible Disclosure Policy

#73

Earlier quoted context omitted.

Actually, the world _does_ stop turning because it's Sunday. Anything happening on the weekend is emergency management, which takes time to scramble. I work in network/information security, and if we had a security incident on a Sunday, it would go to our backup team (of one). If they (he) deemed it critical, they would notify the security director, who would notify my boss, who would notify the rest of the team. Thi…

> Actually, the world _does_ stop turning because it's Sunday. Incorrect. In Islamic countries, which are a part of this world, like Saudi Arabia and Oman have Thu-Fri weekend. http://en.wikipedia.org/wiki/Workweek_and_weekend#Islamic_co...

I think it could be reasonably inferred that when someone says "the world stops turning", it's being used metaphorically. Kind of like "stop the presses".

Re: Responsible Disclosure Policy

#74

The thing I haven't heard a straight answer on is 1) how long has the bug existed, 2) have they proved that it wasn't previously exploited.

1) Given the nature of the bug "for ever" seems like a good guess 2) I doubt they can prove any such thing.

Re: Responsible Disclosure Policy

#75
post #70

What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…

>the compromise of an account not held by him puts him clearly into the "black-hat" category.

That's not what "black-hat" means.

Re: Responsible Disclosure Policy

#76

I hate to be the one pointing out this but it's a shame that a company like GitHub will reward responsible disclosures just with a thank you and the promise to not pursue a legal action. http://help.github.com/responsible-disclosure/ "white hat researchers are always appreciated"

[deleted]

Re: Responsible Disclosure Policy

#77
post #32

Earlier quoted context omitted.

If what you're implying here is that they should be offering a bounty for discovery of bugs, I'm not necessarily disagreeing with you, but to expect them to get a policy about that and to allocate funding for those bounties on a Sunday, within 24 hours of a major, public breach seems a little unreasonable.

I'm with you but still it's silly they didn't have a responsible disclosure program until today in the first place.

They did.

Re: Responsible Disclosure Policy

#78
post #72
post #70

What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…

The vulnerability was public, known for years, and no doubt already exploited. Making a splash about it on GitHub, popular as it is with rails hackers, is the best thing that could happen to the security of the rails ecosystem.

The class of vulnerabilities was known but not this particular case. That's like saying people should be publish 0-day buffer overflows because it's a known vulnerability class.

Re: Responsible Disclosure Policy

#79
post #70

What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…

>the compromise of an account not held by him puts him clearly into the "black-hat" category. That's not what "black-hat" means.

Yes it does.

Gain unauthorized access to an account and using it falls under pretty much any standard definition of "black-hat" and in practical terms breaks computer security laws in pretty much all legal jurisdictions which have them.

Re: Responsible Disclosure Policy

#80
post #70

What the guy did was not only morally irresponsible but also criminal. The security community has long has an accepted standard of responsible disclosure, which involves informing the vulnerable party beforehand and allowing them time to fix the problem before publicly disclosing it. Publishing a vulnerability before giving those vulnerable a chance to fix it is irresponsible, using it to compromise a system is crimi…

>the compromise of an account not held by him puts him clearly into the "black-hat" category. That's not what "black-hat" means.

[deleted]
Post reply on HN