> Apart from that, we couldn't find any alternative way of reaching you.
I'll just be blunt, I find this very hard to believe.
I want to take a moment to express why I feel the way I do. If you were a random security researcher, then great. You tried to contact me, the emails got lost along the way. There isn't much you can do. But from what I can see, you're a member of the Lua community who actively uses LuaRocks.
Did you stop using LuaRocks while you were aware of this issue? Did you instruct other people not to use it within rocks.nvim? For all you knew, every module on the site could have been replaced with malware infecting anyone installing any package. The severity of this was a "drop everything and panic" scenario, not an "I asked a group chat, oh well."
When you say something like, "Apart from that, we couldn't find any alternative way of reaching you," it makes me scratch my head. I am grateful you tried to contact me, but statements like that make it hard for me to give you the benefit of the doubt regarding your attempts to contact me.
And that doesn't event address the parts you glossed over in your account of the situation, specifically the actual exploitation on the production server without clearly stating that from the get-go.
> I'll just be blunt, I find this very hard to believe.
Email was the primary contact mechanism listed in the SECURITY.md file on GitHub. On your GitHub profile, you have listed links to socials (Mastodon/Bluesky/Twitter), your e-mail address, your personal website, and a video game website.
Messaging or tagging you there about an unpatched RCE would have effectively been a public zero-day disclosure, which we strictly wanted to avoid.
> Did you instruct other people not to use it within rocks.nvim?
That, too, would have been a public disclosure. All we knew at the time was that there appeared to be a second security researcher testing your site. In such situations, when there exists no perfect way to handle things, it's better not to "drop everything and panic", and to attempt *private* outreach via *defined* channels.
> statements like that make it hard for me to give you the benefit of the doubt regarding your attempts to contact me.
Rather than going back and forth on motives, how about we focus on establishing a clearer direct line of communication for the future?
> specifically the actual exploitation on the production server
Since I did not conduct the research myself, I am not in a position to comment on the technical details of it.
Much appreciated
> Messaging or tagging you there about an unpatched RCE would have effectively been a public zero-day disclosure, which we strictly wanted to avoid.
No one is saying that, huh? Are we following the same timeline? At this point you have emails out to me a Hisham. You aren't hearing back from us, it's been a while. The issue seems pretty bad. Any way of nudging either of us to check, "Hey, something important about LuaRocks, check your email" in a dm, or a message to anyone else related to LuaRocks. There's a million ways to get my attention without publicly disclosing the issue. Dang, even you could have sent an email.
> That, too, would have been a public disclosure.
I wasn't suggesting you publicly disclose. I'm trying to understand how you understood what was at stake. You have your own community of users with rocks.nvim consuming files through luarocks.org that would potentially be installing malware. I also asked you "Did you stop using LuaRocks?" I'm trying to assess if you just didn't see it as that severe of an issue.
Look, I fully accept your defense of "We did what was in SECURITY.md. Not our fault that the emails were never delivered. Anything else is outside our responsibility. " If you're just some random security researcher, I accept it. My argument is that you aren't a rando and you're more tied to the ecosystem, and have more responsibility. But maybe you disagree.
> Rather than going back and forth on motives, how about we focus on establishing a clearer direct line of communication for the future?
Yes, thank you! I've been waiting for email from anyone at this point. I tried to get info from Vhyrro way before this HN thread but got ignored https://github.com/vhyrro/luarocks-rce-proof-of-concept/issu...
> Since I did not conduct the research myself, I am not in a position to comment on the technical details of it.
You have enough intimate details of the situation to participate in a multi-day conversation with me on behalf of Vhyrro's work but conveniently don't know anything else? Were you a politician in another life? :)
I will follow up with your email, thanks
Sorry for all the snark, I hope you can at least empathize a little with my situation.
That is exactly what Vhyrro tried to do on Matrix. The room had active messages from July/August and no notice of departure, so we had no reason to assume it wouldn't reach you.
> or a message to anyone else related to LuaRocks
That's how we got the link to the Matrix/Gitter room in the first place.
> Were you a politician in another life?
No, but I've been told my great-great-grandad was :)