-
-
Replying to @ManishEarth @hdevalence
I know it had at least been posted on their forum. Was not aware of the other cases. I still stand by the statement that anyone in our industry should know better, and if it was ignorance we need to do a better job of teaching this.
1 reply 0 retweets 0 likes -
Replying to @sgrif @hdevalence
Manish Retweeted Sarah Jamie Lewis
Yeah, I don't think it was ignorance, nor do I think it was immoral (seems like Henry is of the same opinion?) I kinda agree with Sarah here. I personally would privately disclose but I don't consider this specific case immoral to not.https://twitter.com/SarahJamieLewis/status/935700213074817025 …
Manish added,
2 replies 0 retweets 2 likes -
Replying to @ManishEarth @hdevalence
Immoral is much stronger than what I was trying to express.
1 reply 0 retweets 0 likes -
Replying to @sgrif @hdevalence
Improper/immoral/unethical/or basically "wrong" in any way.
1 reply 0 retweets 0 likes -
Replying to @ManishEarth @hdevalence
I think the difference in my point is this: I don't see this as a disclosure, I see this as a disclosure to the developers working there who aren't magically more powerful than the developers working on OSS. I reject the notion that throwing more money at it fixes the problem
1 reply 0 retweets 0 likes -
That does not make it OK that this happened, nor does it mean the reporter is responsible for the problem (that very squarely falls on Apple's shoulders), but I do think that it is only fair that the developers be given a chance to correct before it is made publich
3 replies 0 retweets 1 like -
That said, I think all disclosures should come with a timer. There are far too many stories of disclosures being ignored for months or even years
1 reply 0 retweets 1 like -
TL;DR: Working for a billion dollar company does not magically give you anti-security issue super powers as much as we would like it to. If private disclosure makes sense for OSS, it makes sense for private companies as well.
1 reply 0 retweets 0 likes -
Replying to @sgrif @hdevalence
You're drawing a private-company vs OSS distinction that I am not. I'm talking about this specific case and it has more to do with the widespread use of operating sytems, lack of updates being heeded, and the fact that this vuln was public already.
1 reply 0 retweets 0 likes
All I knew about was the forum post. I'm not well informed enough about how public it was to really make an informed opinion about this specific case it seems.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.