• 0 Posts
  • 41 Comments
Joined 1 year ago
cake
Cake day: January 6th, 2024

help-circle




  • I’m genuinely curious what you would call this and what distinguishes it from a vulnerability.

    Leaving aside responsibility, the system could have been set up in a way that wouldn’t have exposed user data but wasn’t. This is now fixed and user data isn’t exposed via this method any longer. What is the right word for what it was at the moment this flaw was discovered?



  • It sounds like she’s very upset that Dansup made it explicit that he was fixing this issue, thinking that even exposing it in commit comments (which as we know get way more readership than blog posts) would mean people knew about it, and the less people that knew about it, the safer her partner’s information would be since she is continuing to do this apparently. You will not be surprised to discover that I think that type of thinking is also a mistake.

    I agreed with you at first because from your description it sounded like she was saying security through obscurity was a good thing. But that’s not the case.

    What she’s saying in the blog post is that this a 0-day and should be handled according to the best practices for 0-day disclosure.

    You have to decide if you want to

    • publish the findings before the fix -> more people will know and exploit the vulnerability but users might be aware and may or may not be able to mitigate sharing even more
    • publish the findings after the fix -> the opposite

    I don’t pretend to know enough to judge which option is the best. But I can’t fault the blog author for pointing out that Dansup didn’t follow best practices.












  • I’d say it also turns off people who have expertise in other areas and would chime if there wasn’t so many hurdles.

    Say an astrophysicist wants to connect with the community. Do you think they want to take time out of their day to learn the intricacies of a tool that otherwise has no use to them? Do you think they should have to?

    This will inevitably keep this community gated from having a diverse userbase that Reddit has had at its peak.