:flan_hacker: is a user on bsd.network. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.
:flan_hacker: @florian
Follow

responsible disclosure Show more

· Web · 20 · 22

responsible disclosure Show more

@florian if people are going to continue to proclaim that embargoes keep the world safe they need to start providing hard data to back it up.

"Responsible" disclosure is just another Good Old Boys club. Who gets to decide which parties are involved in the embargo? It's certainly not a democratic process open to the public. I'm certain there are bad guys getting access to the embargoes by now via corporate espionage.

@feld @florian Exactly. I think that some people stand on some childish behavior once again too...

@feld @florian
Maybe responsible disclosure is a poor choice for hardware bugs.

But for software ones, I think it's obvious that if you're going to notify someone early, it should be the vendor of the buggy software and nobody else.

I'm no expert tho, maybe the reality is different.

@Wolf480pl @feld @florian The reality is that most vendors care more about their reputation and profits than about the security of end users. Security only becomes a problem when it risks damaging either of those two. Vendors in general don't do proactive security. Not because they are malicious, but because their business models don't allow for it. The industry as a whole is ill equipped to deal with security issues. Just look at the state of IoT.

Embargoes exist to help uphold this system.