Why is the cyber industry so desperately stupid for attention?
Why is the cyber industry so desperately stupid for attention?
Yeah, they don't have the latest door chain and fancy security systems, but that just means they don't open the door to random people who come knocking and are more careful and wary of burglars.
Now imagine a real estate company paying people to try and break into houses like theirs in order to scare the people into spending money and moving to a bigger and newer house they don't want to move to, claiming that the people don't know any better and need to be FUD'd for their own good.
That sounds like an evil thing to me.
After 25 years of this debate it's pretty clear what works.
It might put pressure on customers to demand products with longer support lifecycles, which in turn forces vendors to offer longer support and/or make their software and APIs open source once support ends.
It won't. It'll allow vendors to put pressure on customers to buy new shit to replace their old shit that still works just fine that the vendor would rather not spend the resources patching.
I rather have as many "known" 0-days in the open. Then having it the other way. Even if it means I won't see any updates to affected devices or software
Burglaries aren't getting enough attention.
Do you think devices are retired because they aren't sold? Why would you want that information to be known only by bad actors? Just imagine trying to convince someone who mounted a beautiful android 4.4 tablet to control their smart home (heh) 5 years ago that they will have to redo every thing because they bought into a proprietary protocol and the base os isn't receiving security updates.
Or do you truly believe you are safe if you hide under your bedsheet?
Giving ransomware actors free bugs for mass exploitation when they are unlikely to be patched is just putting innocent users in harms way. It doesn't really make a dent in the shit vendors' profits, so the only other motives are 1) to show off your cool research or 2) protest ridiculous EOL deadlines (which sure, might make a difference).
You're advocating security through sticking-your-head-in-the-sand.
You want to play with something you don't own or have permission to play with it.
Assassinate target. You want to make money/fame off others. DIE.
If somebody came to you house and started jiggling doorhandles what would you do?
Why is cyber different?
NO CONSEQUENCES.
I agree putting such burdens on companies with little IT resources isn’t healthy for the company, its customers or anyone else. This is hostile.