Slashdot Mirror


Full Disclosure and Why Vendors Hate It

An anonymous reader writes "Well known iPhone hacker Jonathan Zdziarski gave a talk at O'Reilly's Ignite Boston 3 this week in which he called for the iPhone hacking community to embrace full disclosure and stop keeping secrets that were leading to the iPhone's demise. He has followed up with an article about full disclosure and why vendors hate it. He argues that vendor-only disclosure protects the vendors and not the consumer, and that vendors easily abuse this to downplay privacy concerns while continuing to sell insecure products. In contrast, he paints full disclosure as a capitalist means to keep the vendor accountable, and describes how public outcry can be one of the best motivating factors to get a vulnerability addressed."

16 of 91 comments (clear)

  1. Well of course by eneville · · Score: 4, Insightful

    It's pretty obvious since vendors have to do more work and package another release to fix bugs. It's easier to keep this information secret and just bundle all the bug fixes into a bulk package when it suits the vendor (I expect money comes into this equation somewhere).

    1. Re:Well of course by manwal · · Score: 5, Insightful

      It's only about money. With few or no public security flaws/fixes, your company, product and brand look safe. With many, they look dangerous. It doesn't matter that security often works the other way around.

    2. Re:Well of course by Adambomb · · Score: 3, Interesting

      (I expect money comes into this equation somewhere) Development costs for the fixes and effectively retooling costs for the production line. I would expect that making a new master and swapping it up in pressing wouldn't be the big portion of the cost, but its there.

      Of course companies hate the concept of full disclosure. That would not allow them to make patch timetables based on business needs as opposed to customer needs. But then, I'll never understand why consumers accept the concept that businesses need to keep such secrecy in the name of security through obfuscation, and then smile and nod when things fall apart that "yep dealing with computers for you".

      Why in the hell has this become one of the few fields where its considered normal to have a broken product? Granted its nigh impossible to have a 100% bug-free product, but the standards seem to keep falling and falling.
      --
      Ice Cream has no bones.
    3. Re:Well of course by davester666 · · Score: 3, Interesting

      It's not just about security. It's also about features. Things like the broadcast flag. Like the analog bit that accidentally got set by NBC that Microsoft implemented support for to disable recording some shows. Hell, both MS and NBC said it was a mistake that the flag was turned on. But even though there is no legal basis for even noticing that flag, Microsoft did NOT say "we'll update our software to ignore that flag".

      You don't know what agreements have been made between Microsoft, Tivo, other DVR manufacturers, the Cable companies and big media such as Universal and the other movie makers. But 5 years from now, when they happen to decide to use these secret broadcast flags, the consumer can't buy a DVR that doesn't implement these flags. There's no legal basis for say, not permitting the end-user to record a movie, except you can't buy a device that will do it.

      And who do consumers complain to? Microsoft? Based on what Bill Gates said about music DRM, they'll just say "We just wanted to enable our software to play movies, and we just let the content provider decide what permissions/features they will license to the consumer." Same with the Cable companies. Movie companies would just say that's how Movie X was licensed from the production company [and don't mention that they own the production company].

      Do you think the new CableCard 'standard' is any different? The FCC keeps harping that things like this should be worked out in the private sector. Except, when working things out, one particular group tends to be completely left out of the discussion, namely the consumer.

      --
      Sleep your way to a whiter smile...date a dentist!
  2. Incredibly Inflated Sense of Self Worth by NDPTAL85 · · Score: 4, Insightful

    This guy really thinks highly of himself. He claims the iPhone's "secrecy" or Apple's inattention to the "privacy flaws" have hurt the product.

    Ridiculous.

    The biggest complaints about the iPhone are the lack of 3G, lack of GPS and no current support for cut and paste or MMS.

    I've never seen someone anywhere complain that its insecure and vulnerable to hackers.

    --
    Mac OS X and Windows XP working side by side to fight back the night.
    1. Re:Incredibly Inflated Sense of Self Worth by JustNilt · · Score: 3, Informative

      The biggest complaints about the iPhone are the lack of 3G, lack of GPS and no current support for cut and paste or MMS.

      This is somewhat true. The average consumer simply isn't aware of the security issues with most things they use. It doesn't matter whether it's their phone, their computer or their front door locks. This is actually kind of the guy's point. Companies are able to keep people in the dark at will, generally.

      I've never seen someone anywhere complain that its insecure and vulnerable to hackers.

      That's funny. Here's a link to a Forbes article from last summer regarding a lack of security.
      http://tinyurl.com/2huxru

      Here's another link regarding an actual exploit vector, reported by the New York Times: http://tinyurl.com/2uk6vy
      Here's the link to the discussion of this exploit by the very guys who discovered it:
      http://securityevaluators.com/iphone/ (A short URL ... woot!)

      This is with a very cursory search via Google. I've certainly read of these, and other, exploits and issues on the iPhone since its release. What's interesting is most people that actually own an iPhone don't seem to give a rat's ass about security on it.

      --
      You know the thing about UDP jokes? I don't care if you get it or not.
    2. Re:Incredibly Inflated Sense of Self Worth by RAMMS+EIN · · Score: 5, Insightful

      ``Which proves this article's premise completely wrong. The only people who ARE interested are the malicious folks, which will be almost your entire "full disclosure" audience. Full disclosure is a great way to give the malicious folks a head start, and won't do one tiny little thing towards linking a product's popularity to its security.''

      I am offended by your comment. I am in favor of full disclosure, and I am not a black hat. I know there are many people like me.

      Also, your analysis is wrong on both counts. Full disclosure doesn't give anyone a head start. On the contrary, it informs everybody of the flaw at the same time. That does indeed include the black hats, but also the vendor and the users. This allows the black hats to develop exploits, but it also allows the vendor to work on a fix, and the users to implement temporary stopgaps. The alternative is, pretty much, not informing the users of the flaw - thereby leaving them unaware that a vulnerability has been discovered. As for the black hats: they work hard to find security flaws and avoid full disclosure - after all, as long as only they know the flaw exists, they can exploit it for fun and profit.

      With regard to linking a product's popularity to its security: I know of two things that will do that. The first is users feeling victimized by the bad security of the product they have. The other is making actual and potential users aware of the security risks of a product. Full discloruse brings the insecurity of a product out in the open, which is a step towards the latter and can also help with the former. Of course, the effect is going to be rather limited as long as users don't care very much, but I can tell you that the effect is there.

      --
      Please correct me if I got my facts wrong.
  3. Peaks by Gracenotes · · Score: 5, Funny

    One of Apple's greatest marketing strengths is this ability to add hype around their products by peaking the curiosity of the common geek.
    As an aforementioned common geek, the misspelling in this sentence is enough to put me in a peak!
  4. That's why we have embargo dates by unixan · · Score: 4, Informative

    I work for a vendor and so I get to see the view from the inside out on this.

    Most times, when a vulnerability is discovered by a professional security group or an upstream vendor, they both tell us what it is, and propose an "embargo" date for when they plan to make it public.

    This gives vendors time to react properly but still serves the public with disclosure.

    --
    This signature intentionally left unblank.
    1. Re:That's why we have embargo dates by Zoop · · Score: 4, Interesting

      As someone who manages an open source product, I get notified (despite ample ways for the "researchers" to contact me) because I have Google alerts for our product's name. I have never, not once, been contacted by the discoverer of a vulnerability or the security groups who publicize exploits.

      This has left me with a very dim view of the security community, and I sincerely doubt the earnestness of the discoverers. They act more like script kiddies out to tag something with their graffiti rather than someone concerned about the consumer.

      Maybe for Apple there are more concerned people out there, but I don't have Apple's resources and would appreciate a couple of weeks to get a fix in and tested before you expose my users to more black hats (as opposed to the black hats who knew about it before).

      I WANT TO KNOW. I WANT TO FIX IT. But the experience I've had so far is that I care more about my users than the security companies and script kiddies masquerading as "researchers" do.

  5. Re:From the article: by Anonymous Coward · · Score: 4, Insightful

    Women's disinterest in IT is as plain and simple as your disinterest for knitting, facials, basket weaving, romance novels and shopping. Genetic differences exist between races and sexes. Stop attempting to impose equality across things which obviously aren't. If 2000 years of history are not enough to prove that women simply have very little interest in technical fields and IT, then you are blind fool. Mind you, this is not to say that women are less competent than men in general, but rather that their competencies have been honed on different subject matters.

  6. everyone hates full disclosure by fermion · · Score: 4, Insightful
    Cyptogram has a discussion of this issue in relation to the oft used argument that only people who have are committing crimes should be afraid of full disclosure. The issue in the note, iirc, related to data mining and video surveillance. The counter example to the statement was the police apparent unwillingness to give tapes of traffic stops, for example, to those private parties involved. It seems that the tapes are there to protect the cops, which is good, but no one is willing to protect the citizen. We see this even in the taping of the very occasional police overreaction.

    Almost no one is comfortable with full disclosure, and the ultimate arrogance and hypocrisy is demanding it in other, while fabricating excuses why your yourself cannot comply. We see this in the current US presidential campaign, where it is typical to release tax returns, but some people feel too above everyone else to so do. This includes other cases where persons who are, like the police, are paid by the american taxpayer, but refuse to fully account for their work hours to the american tax payer. the examples, private and public, are endless.

    So why would geeks, even those that never put on a tinfoil hat, demand full disclosure, especially in a market place where we have the option to simply not spend the money. In this case, if there are significant security issues with the iphone, don't buy one. It sounds trite, and everyone always complains about the philosophy, but it works. MS is a target for viruses, even if it not inherently less secure, so I don't use it on a regular basis. SUVs are less secure as they are not inherently stuck to the ground through the tire patches, and require computer intervention to keep them for tipping over, so I don't buy them. I don't shop at stores with affinity cards. If an iPhone is an attack against security, buy something else.

    Back to the issue of security, there is one serious misconception that I believe many people make. Just because one does not publish ones security details on the internet does not mean that one is practicing security by obscurity. Just because I do not publish my path to work on the net, and my schedule, and the times and places that my stuff is most venerable to theft, does not mean I practice security by obscurity or have a ideological hate of full disclosure. And giving a vendor time to fix an issue, even if everyone except the average consumer knows about it, is not unreasonable. If the vendor does nothing about it in a fairly short time frame, then the equation shifts.

    Which is why the most secure system may be open source. If something is discovered, then an slightly above average user may be able to fix it, and no one has to wait on the vendor. But open source solutions do not seem to have traction in the marketplace, so we are where we are.

    --
    "She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
  7. Re:From the article: by FishWithAHammer · · Score: 3, Informative

    Mods: you done got trolled, idiots. That line does not exist in the article.

    Tip: If the fucktarded anonymous coward CAN'T SPELL, that's generally a good indication.

    --
    "You can either have software quality or you can have pointer arithmetic, but you cannot have both at the same time."
  8. Re:From the article: by FishWithAHammer · · Score: 3, Funny

    Is it Wednesday? I have it on good authority that Wednesday is Rob's turn to enact trollan gaemz.

    --
    "You can either have software quality or you can have pointer arithmetic, but you cannot have both at the same time."
  9. Re:From the article: by Koiu+Lpoi · · Score: 5, Funny

    I totally agree. Since EEE PCs and iPhones are now small enough to fit in the kitchen, we may be seeing a change in this trend.

  10. Full Disclosure - but responsibly by Animaether · · Score: 3, Informative

    Full Disclosure is great - but inform the vendor first.. if they don't take any action in, say, 3 days (I've used that number before - I'm sticking with it) to alleviate it, then hit the internets with it.

    But too often these types are calling for Full Disclosure - immediately! Don't even bother to inform the vendor! RAR! Cry havoc, and let loose the scriptkiddies!

    "The bad guy is already going to test and exploit these vulnerabilities long before the public even discovers them - the good guys ought to have a crack at verifying it too."
    That is an assumption. The assumption that bad guys know about the vulnerability -before- the 'public discoverer' went with full disclosure. Plus the assumption that the bad guys' work would be as bad, or worse than, what script kiddies would do in the time between your discovery and your disclosure. I don't think those are assumption that can be made, based on - admittedly anecdotal - evidence (crashing mIRC 6.something users' IRC application on large IRC networks using a malformed DCC command only became a problem once it was disclosed and everybody and their dog started doing it, while the developer was already in the process of fixing.)

    There's a middle ground - I put it at 3 days. Where do you put it, Jonathan Zdziarski? Your article seems to indicate "0 day", but I can't imagine you being that irresponsible.