Is anyone else annoyed that the WPA2 KRACK paper author sat on it for >2mos before any disclosure and 5mos before public disclosure?
-
Show this thread
-
Replying to @marcan42
No. It's not fair to demand free labour from people *AND* demand they do it exactly how you would like. Why didn't you find the bug?
1 reply 0 retweets 2 likes -
Replying to @zofrex
This isn't about free labour, it's about basic security research etiquette. Sitting on bugs is considered evil.
1 reply 0 retweets 0 likes -
Replying to @marcan42
I sit on bugs. Because no matter how I disclose them, how much work I put in, however I do it, someone like you will call me an asshole.
1 reply 0 retweets 0 likes -
Replying to @zofrex
And I have every right to consider you an asshole to doing that :-) Have you considered anti-user systems? Sitting on those bugs is fine :P
1 reply 0 retweets 1 like -
Replying to @marcan42
Here's the thing: I enjoy reading source code. I notice bugs. How is not disclosing functionally worse than not reading in the first place?
1 reply 0 retweets 0 likes -
It isn't. You're demanding extra work from me or I'm "evil". Nonsense. Don't like it? Pay me, or do it yourself.
1 reply 0 retweets 0 likes -
Replying to @zofrex
He wrote the paper then randomly waited two months. He already did the work. He could've sent the draft to CERT. He chose not to.
2 replies 0 retweets 0 likes -
You ever submitted anything major to a CERT? I did. Still takes months while a shitton of people sit on it and 1 vendor breaks the embargo.
1 reply 0 retweets 0 likes
Yup, I'm sure it sucks, but waiting 2 months doing nothing sucks more.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.