5 ms·
You forget your key when leaving for work, and don't lock your door. It was accidental, you have a lot on your plate. Your neighbour sees you didn't lock it,
by code_sterling 11y ago
You forget your key when leaving for work, and don't lock your door. It was accidental, you have a lot on your plate. Your neighbour sees you didn't lock it, and tweets out, "Hey Mike at 321 Greyhat Bvld, you didn't lock your front door". He didn't send that to you as a text, he tweeted it. You come home, and you've been cleaned out.
I'm sure we can all agree, you should have locked your door. Why be mad at your neighbour, he didn't leave the door unlocked, he didn't take your stuff...
- geofft 11y agoA better analogy would be your doorman, whose one job is to watch who gets into your building, leaving the key cabinet unlocked and going to lunch. I don't mean to blame any individual human here, but I'm baffled at the process by which debugging environment variables were added to dyld without being carefully vetted for bad interactions with setuid binaries. This is a well-known easy place to screw up, and I'm surprised that someone was working on dyld without knowing that (although yes, humans forget things sometimes), and much more surprised that this made it past code review and into a shipping product. This isn't a random screw up in regular software. dyld is security-sensitive; it's one of the small number of libraries that bears a responsibility to be paranoid about setuid.
- odonnellryan 11y agoThat's kind-of a bad analogy. It'd be better of: 1) The person who left the house open was certain to get the message quicker because of the tweet than just a text. 2) It was possible to quickly and remotely lock the door. Apple can and should fix this bug very quickly, as that is certainly possible for them.
- kordless 11y agoI'm sure we can all agree we can make up shit that can happen till the cows come home. I'm not going to act as if someone robbed me until they do. Hold Esser responsible if someone hacks a large number of people because of what he did. Otherwise, stop living a thousands lives.
- byset 11y agoWell, I mean, there were consequences--as the article said, there's now malware out there that uses the exploit this guy publicized.
- kordless 11y agoActually that's not a consequence. A consequence is "200K credit cards were stolen and created $50M in losses". Our assumptions (nay, EXPECTATIONS) that we can achieve a perfect record for responsible disclosure is akin to dissonance, which is why this topic is so polarizing. Let's save the judgement of him until we have evidence that shows why what he did is wrong. Until then, this is all a waste of effort.
- hueving 11y agoAt least read about responsible disclosure before being so flippant about things like that. Esser put people at risk. Whether or not anything happens is irrelevant. He put them at risk and we need to recognize that is the cost of full disclosure. If you're fine with that, cool, but don't pretend he didn't do anything.
- Coding_Cat 11y agoWell, Apple knew about the vulnerability long before Esser reported it though. So "responsible disclosure" whould have achieved nothing, so we should not be comparing public disclosure to it, but be comparing public disclosure to no disclosure.
- kordless 11y ago> read about responsible disclosure Stop presuming I haven't. > Esser put people at risk. That's non-provable until we see it instantiated. > If you're fine with that, cool, but don't pretend he didn't do anything. Don't speak for me. I never said he did the right thing. I said stop spinning what-ifs about it, but clearly what I should have said is STFU and do something about it. People getting in each other's grill isn't doing something about it. It's blaming others for whatever issues we, as a group, find polarizing.