The Post-Snowden Cyber Arms Hustle
bloomberg.com
The Post-Snowden Cyber Arms Hustle
1–7 of 7 posts
Re: The Post-Snowden Cyber Arms Hustle
#2But I can't help but compare these guys to this guy[1] who was on the front page of HN 2 weeks ago. He privately disclosed the vulnerability, then waited 12 days then publicly disclosed it on his blog. And there was widespread outrage and condemnation of him for daring to disclose that quickly, putting users at risk. He was described as "a parasite on society". Well if someone who privately discloses then waits 2 weeks and publicly discloses is a parasite, what is someone who sells exploits to oppressive countries that kill journalists? With that comparison, the discloser seems downright virtuous.
Re: The Post-Snowden Cyber Arms Hustle
#3Very interesting article, and funny in a dark way. But I can't help but compare these guys to this guy[1] who was on the front page of HN 2 weeks ago. He privately disclosed the vulnerability, then waited 12 days then publicly disclosed it on his blog. And there was widespread outrage and condemnation of him for daring to disclose that quickly, putting users at risk. He was described as "a parasite on society". Well…
The standard is something like a minimum of 30 days (usually more) upon confirmation receipt. He never saw someone acknowledge the disclosure, so McDonalds' security staff could justifiably say they were not aware and couldn't have done anything.
Responsible full disclosure, like how Google's Project Zero reports bugs, is the best compromise.
Re: The Post-Snowden Cyber Arms Hustle
#4Very interesting article, and funny in a dark way. But I can't help but compare these guys to this guy[1] who was on the front page of HN 2 weeks ago. He privately disclosed the vulnerability, then waited 12 days then publicly disclosed it on his blog. And there was widespread outrage and condemnation of him for daring to disclose that quickly, putting users at risk. He was described as "a parasite on society". Well…
Full disclosure is not what people had an issue with there. The problem is he only waited 12 days, and didn't really try hard enough to confirm someone at McDonalds was aware. The standard is something like a minimum of 30 days (usually more) upon confirmation receipt . He never saw someone acknowledge the disclosure, so McDonalds' security staff could justifiably say they were not aware and couldn't have done anythi…
You can't really compare an individual person with Google. Google employees are being paid to do that, so of course they can spend all day trying to contact companies, it's their job to be professional. And they probably have databases of high level security contacts at most companies. And any company will likely take a contact from Google seriously, but possibly blow off a contact by some random guy.
Re: The Post-Snowden Cyber Arms Hustle
#5Very interesting article, and funny in a dark way. But I can't help but compare these guys to this guy[1] who was on the front page of HN 2 weeks ago. He privately disclosed the vulnerability, then waited 12 days then publicly disclosed it on his blog. And there was widespread outrage and condemnation of him for daring to disclose that quickly, putting users at risk. He was described as "a parasite on society". Well…
Full disclosure is not what people had an issue with there. The problem is he only waited 12 days, and didn't really try hard enough to confirm someone at McDonalds was aware. The standard is something like a minimum of 30 days (usually more) upon confirmation receipt . He never saw someone acknowledge the disclosure, so McDonalds' security staff could justifiably say they were not aware and couldn't have done anythi…
http://venturebeat.com/2016/10/31/google-discloses-actively-...
Re: The Post-Snowden Cyber Arms Hustle
#6http://motherboard.vice.com/read/the-forgotten-prisoner-of-a...
Interesting that Kumar wouldn't speak to that reporter and was characterized as a criminal and scammer by others.
Re: The Post-Snowden Cyber Arms Hustle
#7Earlier quoted context omitted.
Full disclosure is not what people had an issue with there. The problem is he only waited 12 days, and didn't really try hard enough to confirm someone at McDonalds was aware. The standard is something like a minimum of 30 days (usually more) upon confirmation receipt . He never saw someone acknowledge the disclosure, so McDonalds' security staff could justifiably say they were not aware and couldn't have done anythi…
Google can undercut that. They disclosed MS vulnerability after only 10 days. http://venturebeat.com/2016/10/31/google-discloses-actively-...