Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Funny, I wrote a blog post about this as well.[1]

Vulnerabilities do not need PR, especially not on the scale of picking a sexy name and making a cool logo. I'll repeat what I said in my blog post here.

Branding vulnerabilities accomplishes two things, both of which are bad for the security community and the broader tech community:

1. It implicitly establishes vulnerabilities as severe if they are widely reported on. Getting media attention does not necessarily mean a vulnerability is serious. It means you have content that will generate views. I’ve been in the press twice for vulnerabilities found in widely used web applications – neither I or anyone who is even remotely familiar with security would claim that media attention elevates a vulnerability to the same level as Heartbleed. But the broader public doesn’t know this, and the media capitalizes on it.

2. It implicitly rates a vulnerability’s severity by how much attention and “buzz” it generates, not by how severe it is according to an objective scale. Yes, Heartbleed and Shellshock were severe. Did you know that all the vulnerabilities that received bounties from The Internet Bug Bounty Program were also severe? They didn’t receive media attention. They didn’t need to receive media attention – the normal process of responsible and coordinated disclosure is enough (and I’m willing to say that for extremely high-severity cases like Heartbleed, a brand may be warranted – but not for anything less).

Having widespread press attention via a logo and a name is just another noisy metric that will soon be added to the list of necessities for a vulnerability to have any credibility. Michal Zalewski and Project Zero find vulnerabilities on the scale of the so-called "GHOST" weekly. They are resolved without the need for panic or self-promotion.

This activity, like all fame seeking in the infosec industry, is encouraging a race to the bottom where people focus on the wrong things to decide is a vulnerability warrants attention. For every legitimate Heartbleed and Shellshock, there are the 20 vulnerabilities people try to brand put on the front page of Hacker News and /r/netsec.

[1]: http://breakingbits.net/2015/01/27/your-vuln-does-not-need-a...



While I can agree about over-hyping things, I've seen a lot of really, really ancient crap finally getting much-needed upgrades due to some of the hype, like Debian Lenny, which hasn't had security updates for 3 years now.

Marketing vulnerabilities doesn't really sit well with me, but at least there's something of a silver lining. More people are actually paying attention to security and at work I've been helping clue people into better security practices. The status quo is pretty sad.

Though I grant I've seen some nonsense, too, likely generated by some sort of hype. For reasons I cannot explain, a lot of people suddenly want to do mutual auth against any old public CA-issued cert. It's not as if anyone can run s_client, find all the trusted issuers listed in the ServerHello (and possibly other random certs, because some people put the whole chain in there), and pay the CA a few bucks for a cert to auth with.


Lenny didn't get a security update for ghost. What you're thinking of is the LTS support effort [1] for a limited set of packages. It is maintained by a team of volunteers and is not an official project. Libc6 has had a few security upgrades by the LTS team in 2014. See both squeeze and LTS changelogs [2] for a comparison. It is important to note that if people still run squeeze they will NOT have LTS support out of the box, it has to be configured manually.

[1] https://wiki.debian.org/LTS

[2] http://metadata.ftp-master.debian.org/changelogs//main/e/egl... http://metadata.ftp-master.debian.org/changelogs//main/e/egl...


Sorry, I'm not being clear here. I mean they were upgrading the OS to something newer, I'm not saying that Debian is (or should be) updating Lenny.

That aside, it seems like you can use the squeeze-lts packages on Lenny.


I feel this is way too optimistic. Who doesn't own a few devices (especially routers and cellphones) that probably aren't ever going to get much-needed security updates from the manufacturer? I'm very for any PR about how not-okay this type of situation is.


I feel the opposite, or that your optimism about exploiting the GHOST vulnerability is silly. PR firms aren't paid for good judgement. Lets see your cellphone and router exploits for GHOST, and then worry. Since you bring up cellphones how about these vulnerabilities http://www.extremetech.com/computing/170874-the-secret-secon... These sound much worse. You can brick a phone etc.


Yes, cellphones and routers are not affected, but this is only because they use BusyBox etc not glibc.


That's a non-sequitur -- busybox isn't a replacement for glibc. In fact, the busybox package included with Debian is linked against glibc, and I would assume the same is true for most other distributions.


Sorry, I should have mentioned uclibc instead.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: