Hacker News new | past | comments | ask | show | jobs | submit | DrJaws's comments login

maybe the workforce is not really behind the non-profit foundation and want shares to skyrocket, sell, and be well off for life.

at the end of the day, the people working there are not rich like the founders and money talks when you have to pay rent, eat and send your kids to a private college.


I feel more like companies "worried" about disclosure to governments in 24 hours worry more about needing to fix things fast and maybe hire more people to do it than from security concerns issues.


I feel more like companies "worried" about disclosure to governments in 24 hours are "worried" less about the 24 hour and more about the disclose part.

Their preferred outcome would be mandatory disclosure within infinity hours.


This is a very simplistic take. There are CVEs and then there are CVEs. Some may take months to be properly fixed, no matter how many engineer-hours you put on them (e.g. the entire side-channel attacks saga). And that's not even taking into account the time required to alert different vendors (think about all the different linux distributions, upstream, big companies, etc...) and coordinate adequate steps.


None of which matters if it is active exploit, which not only the government but users fo the software should be made aware of even if no patch is avalible yet, this will allow them to make the choice to shutdown the system, apply network level or other security measure, increase monitoring or many many many many other things they would be unable to do if software vendors keep it hidden for months while they choose what is the best course.

I am fundamentally a full disclosure supporter.


Don't you think governments need to know if their software has a known actively exploited vulnerability that exposes their private data, especially if you are going to take months to fix it? Or are you saying it is fine to stay silent if you notice Russians are using an exploit reading private user data and it will take months for you to fix it?


You make it sound as if the maintainer team already has a near-complete understanding of the problem in the first hours.


Not sure what you mean, if you know you have an actively exploited vulnerability then what more investigation would you need to do in a few hours?

This law only talks about actively exploited vulnerabilities, if you find a bug and go home for the weekend without fixing it that should be fine since that bug isn't actively exploited.

Edit: Point is, once you have done the investigation necessary to know that it is actively exploited you already have a ton of understanding about the problem. I don't see why you would need more than 24 hours at that point just to write a report to affected actors.


Suppose that I'm actively exploiting your software. Then I'm in a position where I can describe the exploit, but you may not be. After all I'm hardly eager to tell you how I'm doing it.

Once you discover that it's happening, you know there is an exploit so you know at least that the vulnerability exists. The discovery probably tells you something about the vulnerability, but how much? The last one I heard about in any detail was discovered when they noticed that an uplink was at 100% utilisation and realised that it was due to data being exfiltrated. That didn't tell them much about how the intruder gained the ability to exfiltrate the data.

Do you know enough to describe it? I know enough, but you're the one who's required to write a notification. Can you describe the vulnerability that's the subject of your notification?


It's easy.

Just report whatever you knew already. ... and prepare to join endless meetings with no time work on the problem. /s


Even if they knew, what would they do about it? It's not like "the governments" could pull up a Spectre patch out of thin air. There are no mitigations. So what do they gain from knowing if they can't avoid it anyways?


There are mitigations for many vulnerabilities that don't involve the software being patched. For example, once you know a particular vulnerability exists, even if it's unpatched you can monitor for attempts against it, modify firewall rules and process monitoring to improve your awareness, etc.


It’s not uncommon for groups like CISA to recommend blocking things from the internet or disabling a particular feature which is part of the exploit but not critical to the entire app. They also proactively notify users in some cases (e.g. industrial systems) so everyone knows to install the patch as soon as it’s released.

As a simple analogy, look at how the Kia lock vulnerabilities are being handled. Yes, it’s best if you can repair everything but it’s not without value to make sure everyone affected knows the risk so they can change their behavior or buy a separate lock until then.


> There are no mitigations

They can use different applications and communication channels to avoid leaking data to hostile governments.


> There are no mitigations.

What about, everybody stops using the defective software? Or, more conservatively, all EU governments stop using the affected products?


> Even if they knew, what would they do about it?

Call meetings. Join endless meetings. Make deadlines for more meetings.


Also, there are governments and then there are governments. I would rather have a company keep zero-day a secret than disclose it to government run by assholes such as Victor Orban or Emmanuel Macron.


Reports of security breaches need to be reported to ENISA which is an EU institution.


Keeping multi month ones secret is even bigger risk to security if workarounds exist.


> fix things fast and maybe hire more people

I really hope you don't work in software.


chat-gpt at the end is a language model, not an real AI, it have limits and are huge


What do you even mean by real AI? Some of the top AI researchers in the world work on chat gpt


real AI

Thanks for the laugh, I needed that.


that have a reason, as it's been demostrated by a lot of metastudies you can find on cochrane that there is usually much more worst outcomes and long term effects on the broad of the population when misdiagnosed by overdiagnosing than just simply saving an extra 0.01% (not real number)

the same reason of why for example now there is an advocacy to end yearly mammograms on older woman, because the number of them saved by that practice is inferior to the ones that are misdiagnosed and then put under other unnecesary medical practices that end up hurting more by unnecesary practices on a lot of them that would have never developed a cancer or under pressure to the ones that no one will be able to save no matter how sooner they got the diagnostic.

infinite constant and unnecesary medical tests is not the way for now, maybe in the future, but not now.


Isn't this more a product of relative rarity of this type of imaging & average doctor not knowing how to react properly other than escalation?

Not ever spec on an image should mean cutting someone open or blasting with radiation.


I think that it's more in the line of

- I jumped some walls that others won't be able because I knew the right people as we work together and they dedicated some of their personal time and public funds to help me, but they won't do it for you

but without sounding like he used the privileges he really had


HiFiMAN has really destroyed the audiophile market for other brands. Every single bracket of their products perform like any other company +50% extra price product

Sundaras were amazing, but the new edition XS were just the last straw for competitors, never a headset of that quality was so affordable, the equivalent from other brands can even cost 2x the price.


this is brilliant


Welcome to costco, I love you

sorry couldn't help myself...


That all contributes to its image as a high-class discounter. That's fine, it just breaks apart where you say "Welcome to Aldi. You exist." Or "Welcome to Kroger, we love you as long as you buy the six things on sale, but after that we need to talk."


I believe they were referring to this scene from Idiocracy: https://youtu.be/ZIFCWpn4qQ4


Yes, I'm aware, but our brave new future, in its magnificence, has multiple grocery retailers.


This reminds me a lot to FS mental models, they even have some books

https://fs.blog/mental-models/


this is important to the war, everybody knows that those who control the mutant faction, will win the war


Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: