Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At the same time, it's a real "damned if you do, damned if you don't" situation, isn't it?

It is well documented that vulnerabilities are traded and sold freely online at various forums; since this isn't really a 0-day or an exploit as much as it is a new spin on a classic trick, there's no value in malicious actors hoarding the secret, especially since it's mostly a social engineering trick not an actual exploit.

In this particular case, the weight of the options seems to be "Make key users aware and put public pressure on vendors at the cost of giving a few bad actors an idea they didn't have before" versus "prevent giving a few more bad actors a new idea at the cost of Users being in the dark and vendors having no reason to address the issue"

The cost in this case seems pretty minimal, given that I'd assume there's no reason to really hang onto such a tactic.

For other exploits, it's basically the same idea: Who has the exploit, how likely is it that it's been sold, is the vendor likely to do anything about it, how dangerous is it to users? In most cases, if the exploit is already known and used among bad actors freely, what benefit is there to users in keeping such exploits hidden just to prevent a few more bad actors from doing it as well? Just seems like if the house is on fire, there's no sense in worrying about the wallpaper. (paraphrasing the quote since I can't remember its origin)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: