4 ms·
Regarding your analysis as to the actual usefulness of this spec - or lack thereof - I agree. There's not much substance or detail; the result seems like the bu
by developer2 9y ago
Regarding your analysis as to the actual usefulness of this spec - or lack thereof - I agree. There's not much substance or detail; the result seems like the bullet points of an initial PowerPoint presentation for such a concept, rather than the final output of a panel attempting to create a proposal meant to be seriously considered and adopted.
As for the rest of your comment... are you really a "working professional in this field"? By that I'm asking whether you are self-employed and playing fast and loose according to your own rules, or if you instead have an established career within the industry for which your professional peers stand beside your methods? I have to believe that honest professionals with a shred of reputability in this field would not be advocating that playing nice, so to speak, is some altruistic gift on the part of the researcher. "Security Researchers", quoted to loosely include "rogue" grey and black hats who think they have free reign to hack in any way they see fit, have gone to jail for what you appear to be claiming is a risk-free "right". It's not black and white, and the courts seem to favour whichever side suits their fancy in each individual case.
It really bothers me to see anyone suggest that any public port on a machine is 100% free reign to abuse. If public-facing access is all it takes to be free game, then I must be morally and legally in the right to pick the door locks of private citizens and businesses, or peel off the face of any ATM in an effort to "gauge its security". The loophole excuse is that the Computer Fraud and Abuse Act, in theory, only covers computer owned by the government and financial institutions. When all moral obligations are ignored, and skirting around lacklustre laws is the only defence, the intentions of some "researchers" quickly become questionable.
Your stance on the subject is probably fairly common in terms of what people want to be labelled as fair game, while in the real world researchers have to dial back a bit and play nice in order to maintain an ounce of respect in the field.
- SolarNet 9y agoRead what he typed again, you didn't get it the first time. He was pretty clear, in CAPS LOCK LETTERS NO LESS, that the problem here was that this policy was miscommunicating what can be done, as you put it "It really bothers me to see anyone suggest that any public port on a machine is 100% free reign to abuse." He was very very clear that he believes you have 0% right to do that, and that the system proposed in the OP would encourage people to do that, that was his BIG problem with it, so you completely misread what he said (or I suspect, stopped halfway through, about on his fifth paragraph). His comment on responsible disclosure is about the other part of the industry. The one where you install a vendors software on your machine, or where you analyze client code with out their server. As a researcher you have zero responsibility to play nice with the distributors of that content. That's like saying movie reviewers can only print reviews of already released movies on a schedule and in a way approved by the studios (certainly studios - and software companies - are allowed to make deals - contracts - with reviewers for embargoed, or even private, reviews of content before it's released).
- lucideer 9y ago> are you really a "working professional in this field"? > I'm asking [...] if you [...] have an established career within the industry for which your professional peers stand beside your methods? I'm not sure if you're already aware of tptacek's reputation in the field and you're hinting at something different, or if you're asking these questions in a more direct sense. If the latter, I'd recommend checking out his profile and quickly Googling. > in the real world researchers have to dial back a bit and play nice in order to maintain an ounce of respect in the field. Despite what I mentioned above, it may be that this is actually true; that Thomas' reputation gives him a certain level of immunity whereas most "normal" researchers would have to stick to a stricter level of etiquette. All said though, I think SolarNet may also be correct that you seem to have misinterpreted at least some of Thomas' post.
- darksim905 9y ago>tptacek's reputation Could you explain? I never really understood him as an individual & he's been... well, harsh at times to me & others.