> March 19, 2018: Contact Qualcomm Product Security with issue; receive confirmation of receipt
> April, 2018: Request update on analysis of issue
> May, 2018: Qualcomm confirms the issue and begins working on a fix
> March 19, 2018: Contact Qualcomm Product Security with issue; receive confirmation of receipt
> April, 2018: Request update on analysis of issue
> May, 2018: Qualcomm confirms the issue and begins working on a fix
Yet they struggled to get headcount for people to respond to security researchers, and despite having seemingly trained the executives there was a regular "Oh man I contacted legal we should sue this guy!" type email every few months.
Meanwhile they had a separate technical support team who knew how to respond to customers in a timely fashion, make people feel like they're being listened to, but for some reasons they had to reinvent the wheel / fail repeatedly at dealing with security researchers as if nobody had ever done basic customer service before. I was on the support team and I sat next to the security guy(s) and I would show them what to do and how to keep a customer or security researcher on track. It wasn't rocket science, but nobody thought to teach them that.
And that was beyond training engineering to stop with the "well you're using it wrong" type responses.
The scale of, incompetence in the security field is astounding as a lot of folks with security written all over their resume don't know jack squat. And the scale of incompetence just DEALING with security researchers is also bizzaro world terrible, even among companies that should know better.
Having said that the suits have to be in the loop to some extent, they just need to be able to control those "I don't like this sue them" instincts and understand how to better channel that energy.
Security needs an executive level person to be able to directly work with the other executives to push things if only because the inclination to hide or not fix things is so common. Security just isn't a part of a lot of engineering teams mindset / time budget.
While working in a F500, I found on github the company credentials of a security consultant coming from Thales ... hem
The best you can hope for is they likely use Signal, good luck getting their contact details or verifying keys with them though!
Old people can certainly keep up! But corporate climbers often can't (I do know of exceptions)
If their customers (which are not u) and them feel like security is only a cost and not a selling point then they won't work much on it. After all they already sold those products and have orders for more.
It's a cultural thing that just hasn't taken hold (normally I hate using "cultural" but it seems to fit here).
March 20: Confirmation of receipt of issue, boilerplate response detailing expected next steps
And as far as we know, this might have actually happened! Maybe it wasn’t deemed interesting enough to include on that timeline.