As-is, he just seems like a raging hacker who loves attention and doesn't care if thousands of unsuspecting users get their credit card details stolen by malware authors. I must be misunderstanding something, yeah?
As-is, he just seems like a raging hacker who loves attention and doesn't care if thousands of unsuspecting users get their credit card details stolen by malware authors. I must be misunderstanding something, yeah?
I can launch Steam games from my browser without any plugins.
https://developer.valvesoftware.com/wiki/Steam_browser_proto...
Instead, they ask for their interns to build the "solution" that makes my computer part of the Borg.
I really don't feel compassion in this case towards the company (towards the users is a different story, no doubt)
Companies are often incompetant with security code. If you are expecting high quality secure code with consumer level software, you will often be disappointed.
I was saying it seems more likely to me that any random developer making a stupid mistake like this seems more likely than a company having real motivation to create this kind of security hole.
I suppose, alternatively, this could have been an individual developer's intent. An exploit like this would get a pretty penny on the exploit market, I'd think.
The question is: do you believe the perpetrator to be malicious or dumb?
...where at last he installed his Russian Rootkit.
Or maybe some programmer added a feature that was insecure and they moved on to work on some bug that was crashing level three?
Also, that's probably the quickest way to get them to release a fix.
http://en.wikipedia.org/wiki/Full_disclosure
As for your "raging hacker who ...," dig, consider the idea that malware authors already knew about the vulnerability and have been using it.
Do you have any evidence that is the case? The original post didn't mention it.
Otherwise it just sounds like excusing irresponsible disclosure.
http://www.theregister.co.uk/2010/07/22/microsoft_coordinate...
Many believe it is irresponsible to delay informing users that they have a major backdoor exposing them.
That being said, installing a "sudo" plugin in everybody's browser without any security validation (if I understand correctly what this is about) would be hilarious if it wasn't that tragic. But gamers are gamers, they forgave sony, they'll forgive ubisoft too, and they'll never learn.
If the vendor tries to delay you for months or ignores you, sure. But it doesn't even seem like he tested the exploit here to understand whether it was a serious threat.