back

by rdl·16y ago·view on hn ↗
Non-disclosure, vs. Responsible disclosure, vs. Full disclosure (with various levels of warning to the vendor), vs. Aggressive full disclosure is certainly an open point of debate within the security industry. It's pretty unambiguously clear that he didn't use the fruits of the vulnerability in a black hat way to hurt the end users, however.

My personal position varies based on the kind of vulnerability, actual risk to end users, etc. For something which causes minimal harm to the end users (publishing email addresses? really?), which was the result of utter incompetence on the part of a single vendor, and where the vendor can trivially fix it, I think aggressive full disclosure is the right course of action.

If it were something like a flaw in cisco bgp, I would support responsible disclosure, on a very long timescale; give the vendor enough time to fix it, and get the patch deployed to as many users as possible.

If it were a flaw in a no-longer-maintained system which were critical to life safety, I could be convinced to not disclose at all, provided there were something put in place to transition users off of the system.

1 comments
It's pretty unambiguously clear that he didn't use the fruits of the vulnerability in a black hat way to hurt the end users, however.

No and I don't think that accusation has ever been made.

However; he has used the data very unethically and I don't think that it is reasonable for him to claim journalistic privileges or the cover of full disclosure to assuage that.

I have not been following the case, nor am I an expert on security disclosure. Could you expand on how he has used the data and what was very unethical about the uses made?

EDIT TO ADD: Reading your other postings I think you mean giving a copy of the leaked data to Gawker media was unethical. Is that so bad, considering they redacted it and appeared to generally handle it responsibly?

Yes. Your latter point does (and I cant believe I am saying this...) credit to Gawkers handling of the data. But Goatse handed it out (so far as we know, I admit) with no idea of what would be done with it.

Also from a security perspective (at least from mine) it is just unethical to hand over data you got - no matter how trivial :)