The PGP vector is bad enough.
If you're coordinating disclosure, you're supposed to *understand* the interactions between different bits of software, and encourage cross-vendor collaboration to make the impact known and figure out how mitigations are deployed and interact. The researchers totally botched this
-
-
There were massive discussions. GnuPG said not our problem. Enigmail said they understood but then didn’t properly patch and also claimed they didn’t get notified. What exactly do you want them to do differently? Have a public mailing list debate?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
The fact that *I* needed to go around asking some people for info and digging for commits and bugs and mailing list threads to figure out how the fuck this all works and that nobody else did so tells me this disclosure was a massive clusterfuck, and that's on the researchers.
-
The researchers notified every single relevant project. What precisely are you asking them to do differently? They gave months of notice on a handful of bugs with a SIMPLE PATCH.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.