Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
>>> 10-20 years back a term hacker had a close relation to a certain morale conduct emphasizing freedom of knowledge. Agreed. There was a certain "code" people adhered to. Even groups like LOD wouldn't release exploits because they feared people would use them for nefarious purposes.
Full-disclosure – Administrivia: The End
81–90 of 142 posts
Re: Full-disclosure – Administrivia: The End
#82Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
The "hackers" FD's moderator is talking about are the ones I'm talking about. They aren't MIT students ordering sweet and sour bitter melon.
Re: Full-disclosure – Administrivia: The End
#83Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
Yes. This is true. I posted something similar circa 2009 about this sentiment. It used to bother me a lot but not anymore. A reply from pg on the different cultures: pg 1678 days ago | link Everything you've written would have been just as true in the 1980s, with a few of the names changed. Then too there were authentic hackers, glib fakers, and corporate drones. The great majority of the computer world in the 1980s…
Truly PG's lack of self-awareness (or cynical dishonesty) is mind-boggling.
Re: Full-disclosure – Administrivia: The End
#84Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
I don't even know how to respond to the idea that teenagers breaking into phone switches and harassing people, buying Pantera CDs on stolen credit cards, stealing ESNs from other people's phones to make calls on someone else's bill, and rm'ing Unix boxes are somehow more honorable than adults running businesses. The "hackers" FD's moderator is talking about are the ones I'm talking about. They aren't MIT students ord…
Gotta admit, I thought the same thing. Then I'm reminded of patent and trademark law...
Re: Full-disclosure – Administrivia: The End
#85Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
It's at best trying to compare a painter that does portraits to a painter that paints automobiles. Both require skills, but in completely different areas.
Re: Full-disclosure – Administrivia: The End
#86Earlier quoted context omitted.
I don't even know how to respond to the idea that teenagers breaking into phone switches and harassing people, buying Pantera CDs on stolen credit cards, stealing ESNs from other people's phones to make calls on someone else's bill, and rm'ing Unix boxes are somehow more honorable than adults running businesses. The "hackers" FD's moderator is talking about are the ones I'm talking about. They aren't MIT students ord…
> are somehow more honorable than adults running businesses. Gotta admit, I thought the same thing. Then I'm reminded of patent and trademark law...
Re: Full-disclosure – Administrivia: The End
#87http://seclists.org/fulldisclosure/2014/Mar/170
http://seclists.org/fulldisclosure/2014/Mar/294
http://seclists.org/fulldisclosure/2014/Mar/291
http://seclists.org/fulldisclosure/2014/Mar/286
http://seclists.org/fulldisclosure/2014/Mar/298
And a full email exchange: http://seclists.org/fulldisclosure/2014/Mar/index.html#123
My personal favourite (in a positive way): http://seclists.org/fulldisclosure/2014/Mar/160
Re: Full-disclosure – Administrivia: The End
#88Instrumental in this message for me was this part: There is no honour amongst hackers any more. 10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest…
Yes. This is true. I posted something similar circa 2009 about this sentiment. It used to bother me a lot but not anymore. A reply from pg on the different cultures: pg 1678 days ago | link Everything you've written would have been just as true in the 1980s, with a few of the names changed. Then too there were authentic hackers, glib fakers, and corporate drones. The great majority of the computer world in the 1980s…
https://www.youtube.com/watch?v=qHE_XGtUNx4
(Wear Sunscreen)
Re: Full-disclosure – Administrivia: The End
#89Can someone from the security community explain exactly what the list is? Is it a mailing list where researchers disclose exploits that have been found (after doing their best to responsibly notify the developers of the effected systems)?
Yes (vulnerabilities rather than exploits, although these disclosures often contained proofs of concept.) It was the de facto standard vehicle for this.
People seem to believe that happened because vulnerabilities started to obtain a market value, but:
* The serious high-end memory corruption vulnerabilities were (a) more common and (b) much simpler at FD's inception, making them more amenable to posting on a list; in 2014, a high-end vulnerability is likely to be complex enough to merit in-depth consideration on a blog instead.
* Table-stakes XSS vulnerabilities also tend to get written up in blogs (where they help establish a track record for researchers whose future employers aren't going to trawl through FD looking for them), and when they get bought, get bought by bug bounties. It is hard to argue that bug bounties are a bad thing; nobody benefits from a web vulnerability in a SaaS product other than the operator of the SaaS product.
Re: Full-disclosure – Administrivia: The End
#90Earlier quoted context omitted.
Hi, I'm posting this through Tor. The reason I'm able to do this is because this account is more than two weeks old. I also created this account through Tor, so HN's operators should have no idea who I am. For example, you have done an experiment below of posting comments through tor using the newly-created account "throughtor": https://news.ycombinator.com/threads?id=throughtor If you turn on "showdead" in your prof…
We switched to bcrypt several years ago.