Of course the person who improperly disclosed the Apple vulnerability refers to themselves as "Agile Software Craftsman" >_____>
-
-
-
Replying to @hdevalence
They tweeted it rather than disclosing through the proper channels
1 reply 0 retweets 1 like -
-
Replying to @hdevalence
Because they don't involve everyone on the internet knowing about the vulnerability before a patch is available and a CVE is issued
2 replies 0 retweets 1 like -
Replying to @sgrif @hdevalence
When a vulnerability is made public before a patch is available, it's usually referred to as a zero day and is *very bad*
1 reply 0 retweets 1 like -
Replying to @sgrif
I know what 0day is, and I reject the idea that full disclosure is “improper”.
2 replies 0 retweets 3 likes -
Replying to @hdevalence
Sorry, that was more condescending than I intended it.
1 reply 0 retweets 0 likes -
Replying to @sgrif
yeah it’s fine I just reject the idea that the responsibility for the user risk lies with the reporter, who is someone on Twitter, and not with the vendor, who is a company with a $900,000,000,000 market cap
1 reply 0 retweets 2 likes -
Replying to @hdevalence
Gotcha. I 10000000000% agree that something this ridiculous should never have made it into a product with this many eyes
1 reply 0 retweets 1 like
That said, any person in our industry should know better. And if the issue was ignorance, we need to do a better job at teaching
-
-
Replying to @sgrif @hdevalence
What about the reporter’s responsibility to disclose to the public, so those affected can take precautions immediately? Just because the bug is reported through proper channels doesn’t cause it to disappear, and it may in fact already be in use by adversaries.
1 reply 0 retweets 0 likes -
Replying to @noself86 @hdevalence
Miss Dada 🏳️⚧️ Retweeted Miss Dada 🏳️⚧️
Miss Dada 🏳️⚧️ added,
0 replies 0 retweets 0 likes
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.