Slashdot Mirror


User: XparXnoiaX

XparXnoiaX's activity in the archive.

Stories
0
Comments
64
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 64

  1. That's how it should be. The only way we can ever get corporations to be more secure is by hurting them. A little ransom doesn't hurt.

  2. Re:Systemd, WTF? on Interviews: Ask Red Hat CEO Jim Whitehurst A Question (redhat.com) · · Score: 1

    Oh look, an apologist.
    It doesn't matter. There are plenty of bugs in systemd.

  3. Re:The author of this software needs education. on Koolova Ransomware Decrypts For Free If You Read Two Articles About Ransomware (bleepingcomputer.com) · · Score: 1

    The basic ethical principle is to not interfere with another's well-being.

    That's your suggested ethical code. It's not everyone's. Is it ethical to pirate music? To violate copyright?

  4. Re:Systemd, WTF? on Interviews: Ask Red Hat CEO Jim Whitehurst A Question (redhat.com) · · Score: 1

    Now systemd isn't fool proof and probably not bugfree either,

    That's understating it. A simple tweet can crash systemd.

  5. Re:The author of this software needs education. on Koolova Ransomware Decrypts For Free If You Read Two Articles About Ransomware (bleepingcomputer.com) · · Score: 1

    The 'principles' which you choose to base your ethics on are entirely subjective.

  6. Submit it! (after March 1st).

  7. Re:The Backasswards solution on US Government Offers $25,000 Prize For Inventing A Way To Secure IoT Devices (ftc.gov) · · Score: 1

    I favor that approach. When was the last time a company asked you (during a sprint or otherwise) to look at the code and make sure it was secure?

  8. Re:The author of this software needs education. on Koolova Ransomware Decrypts For Free If You Read Two Articles About Ransomware (bleepingcomputer.com) · · Score: 1

    This is not a case of "eliminate all left-handed." You might argue that some ethical systems are not sound, and maybe you would be right, but the crux of this issue (which you seemed to miss in your generalized rant), is that I disagree with his idea of 'ethical.'

  9. Re:The author of this software needs education. on Koolova Ransomware Decrypts For Free If You Read Two Articles About Ransomware (bleepingcomputer.com) · · Score: 1

    Relative to me, my ethics are absolute.

  10. Re:The author of this software needs education. on Koolova Ransomware Decrypts For Free If You Read Two Articles About Ransomware (bleepingcomputer.com) · · Score: 1

    Ethically, this is like pushing someone out of the road so they don't get hit by a car. The pushing might hurt them a bit, but it's way better than getting hit by the car.

    So many people are internet roadkill, they just don't know it yet.

  11. Re:The author of this software needs education. on Koolova Ransomware Decrypts For Free If You Read Two Articles About Ransomware (bleepingcomputer.com) · · Score: 1

    but there is never an ethically appropriate way to damage or steal information that isn't yours on equipment that isn't yours

    It's never legal to do something like this, but ethical? Absolutely. Different people have different ethics, you shouldn't push yours on other people.

    The world needs more education opportunities like this, where they can have a chance to change without actually getting hurt.

  12. Re:Security Theater on Norton Announces Core, a Smart Router To Protect Domestic IoT Devices (cnet.com) · · Score: 2

    It's a good idea, you should have a router protecting devices from the raw internet, but can you really trust Norton to do anything right? Ironically, anti-virus companies don't have a culture of security.

  13. Is systemd insecure? Oh yes, yes it is. It can be crashed in one tweet.

  14. Bad software endangers software development on Does Code Reuse Endanger Secure Software Development? (threatpost.com) · · Score: 1

    The reality is most companies don't care about security.

    When was the last time your boss added a security audit to your sprint? When was the last time someone said, "make sure you add enough time on this task to make it secure."? Security is not a priority for companies, so we don't spend time thinking about it.

    For these reasons I advocate irresponsible disclosure: we need to give companies motivation to improve their code.

  15. Re:When do we switch to OpenBSD? on Ransomware Compromises San Francisco's Mass Transit System (cbslocal.com) · · Score: 2

    It's why we need full and embarrassing disclosure, to motivate companies to take security seriously.

    When companies start failing because of lack of security, then we will see them take it seriously. Not before.

  16. Re:Implementation not protocol on 1 Billion Mobile Apps Exposed To Account Hijacking Through OAuth 2.0 Flaw (threatpost.com) · · Score: 1

    If only the implementation had been written as carefully as the specification. But it won't be, because companies are lazy.

  17. Re:Neel Mehta is a real crumbum on Google Discloses Exploited Windows Vulnerability 10 Days After Telling Microsoft (venturebeat.com) · · Score: 1

    Even if the software developer took every precaution and followed current methodologies to prevent vulnerabilities in their software, there is still a chance that a vulnerability exists.

    My point is that when disclosing, you should take into consideration whether the software developers were following best practices or not. 99% of the time, the answer is: not.

  18. Re:Neel Mehta is a real crumbum on Google Discloses Exploited Windows Vulnerability 10 Days After Telling Microsoft (venturebeat.com) · · Score: -1

    "Arguably" being the operative word. That attitude is extremely naive and borderline criminal.

    The criminal was the company that wrote the vulnerability in the first place.

    If you disagree, and you're a programmer, then answer this: do your managers give you extra time on your tasks to make sure your code is secure? Have they ever encouraged you to care about security, or is it the opposite? Do the encourage you to treat user-input carefully, and as a potential exploit? If your company doesn't do this, then they are negligent.

    Remember there are companies who store passwords in plaintext. That is not only idiotic, anyone with half a brain knows not to do that.

  19. no crisis that hasn't happened on The Next President Will Face a Cybercrisis Within 100 Days, Predicts Report (cnbc.com) · · Score: 1

    What exactly is a cybercrisis? A ddos on a major dns server? Or is it a hack of the DOD? Or is it a hack of the DoJ and DHS?

    At this point, nothing short of poisoning a water supply would be called a 'crisis.' It would be called, "been there, done that."

  20. Re:Neel Mehta is a real crumbum on Google Discloses Exploited Windows Vulnerability 10 Days After Telling Microsoft (venturebeat.com) · · Score: 5, Interesting

    Not only that, the arguably ethical thing to do is to always disclose. In most cases the exploits are being actively used (see previous link).

  21. Re:Because it took five months to fix? on Google's 'Project Zero' Hid A Major Vulnerability in Apple's OS and iOS Cores (thestack.com) · · Score: 1

    Whenever a change is made to the software, especially something as complicated as an OS, you need to allow time for regression testing to make sure the modification doesn't introduce a different vulnerability elsewhere.

    Whenever you have a vulnerability as serious as this one, you better make sure that those regression tests go quickly.....faster than five months.

    Not that I care, iOS should be liberated from its walled garden, and privilege escalation exploits are the way to do that.

  22. Re:How is this a problem, exactly? on Google's 'Project Zero' Hid A Major Vulnerability in Apple's OS and iOS Cores (thestack.com) · · Score: 1, Interesting

    Counterargument. Essentially, there is no way to know that this exploit wasn't being actively exploited (and let's be honest: five months to fix the bug means they aren't taking security seriously).

  23. Re:Is this a record? on Teenager Accidentally Launches DDoS Attack On 911 Systems (softpedia.com) · · Score: 1

    Yeah whatever dude, like you've ever built something that can't be DDOSed. Some security flaws are sloppy but this is hard stuff.

  24. Re:But . . . on Donald Trump Running Insecure Email Servers (theregister.co.uk) · · Score: 1

    This story is deficient: it doesn't have the IP address of the server.

  25. Re:"Gay Culture" is blind devotion then? on Project Include Drops Y Combinator As Peter Thiel Pledges $1.25 Million To Trump (theverge.com) · · Score: 1

    Why, you don't think he's gay? :)