Full-disclosure – Administrivia: The End
marc.info
marc.info
There is no honour amongst hackers any more.
10-20 years back a term hacker had a close relation to a certain moral conduct emphasizing freedom of knowledge. Today with a mass market of startups, that was largely popularized by Hacker News, this perception has changed. A hacker now is a founder. He must be good at raising money, monetizing a product and the greatest feat of all - exit. There's no more moral obligations of the past. Launch at all cost - the rest is an afterthought.
There's a discrepancy between the two cultures. I think this divide is the source of the mailing-list problem and problems with freedom of information and privacy at large we have today.
But it's not the point.
Full-disclosure is all of security-hackers. And the sad thing is that there is no more honour amongst security-hackers. In the 90s they used to share 0-days. Today, well if you don't sell it you're a fool.
I'm so sad I missed that period, IRC, the lulz.
Don't confuse the hacker spirit with the hacker word.
Agreed.
There was a certain "code" people adhered to. Even groups like LOD wouldn't release exploits because they feared people would use them for nefarious purposes.
In short, in the 1990's there were huge amounts of full disclosure, and even those trying to work with vendors were usually snubbed by those vendors. It was a completely different landscape.
pg 1678 days ago | link
Everything you've written would have been just as true in the 1980s, with a few of the names changed. Then too there were authentic hackers, glib fakers, and corporate drones.
The great majority of the computer world in the 1980s was profoundly unsubversive. The smart, subversive people were a tiny minority. They seem a larger proportion when you look back from 30 years later, because the fakers and PHBs had no lasting effects.
10 years from now, who is going to remember Marc Andreessen or Paul Graham? Besides some true hacker enthusiast ironically, who remembers Andressen's work on Netscape. In my original post in 2009, I mentioned the hot founder celebrities back then, Carol Bartz (fired), Seth Godin (pumping out more irrelevant books listed further down on Amazon) and Timothy Ferris (moved on from 4-hour "founding" to 4-hour body-building and cooking).I think in the early nineties, when Linus Torvald first pushed out Linux on the listserv. We had OS/2 Warp and Windows 3.0 preview and Microsoft Bob. Borland, WordPerfect, Lotus 123 running on MS-DOS were the kings. Do you guys remember who founded or worked on those? The people who hack on stuff will always be there because money & fame didn't motivate them in the first place.
Truly PG's lack of self-awareness (or cynical dishonesty) is mind-boggling.
https://www.youtube.com/watch?v=qHE_XGtUNx4
(Wear Sunscreen)
Err. Now I do like that book. But this might be overstating the case.
The Little Schemer
The Seasoned Schemer
SICP
Lisp In Small Pieces
Practical Common Lisp
The "hackers" FD's moderator is talking about are the ones I'm talking about. They aren't MIT students ordering sweet and sour bitter melon.
Gotta admit, I thought the same thing. Then I'm reminded of patent and trademark law...
The only Silicon Valley moral is making money.
I'm weakly willing to bet that whoever you think the "cool kids" were actually sucked.
PLA, 303, cdc/l0pht, DoC ... there was precious little technical skill there (although there was some).
However, I'll take a CuervoCon over a pycon and a swamp ratte stage performance over a Steve Jobs presentation any day of the week.
If your comment reflects sincerely held beliefs that accurately represent the scene as it was, I think it's safe to say you were not a part of it. Your derision of that culture is either out of dishonesty or ignorance.
Claim: for any given period of the hacker scene, saying it largely amounted to nothing more than things like carding and harassment is false, and this statement would only be made by someone who either: (a) was not exposed, or exposed only to a poor sample, and therefore doesn't understand the culture (ignorance); or (b) was exposed, but intentionally wishes to misrepresent the situation (dishonesty)
So I guess the possibilities are either that your statement was ignorant, dishonest, or my claim is wrong and the hacker scene (during whatever time period you intended) was in fact nothing more than dishonorable carders and trolls.
If nothing else, you must know that rming a compromised unix box was not the norm.
What I don't understand is how someone who was around in the 90s could manage to mythologize a bunch of teenagers using semicolons and pipe filters to pop shells on boxes and dump mail spools.
Here's the part where you tell me that you once knew a hacker who never rm'd a box. Why am I meant to care about that? There was zero correlation in the 90s between skill and care for other people's data.
Your opening comment was, "sounds like someone wasn't in the cool kids group". Now you've moved the goalposts; turns out you weren't talking about the "cool kids" at all. But it doesn't matter whether we're talking specifics or the broader issue of whether hackers were more or less moral in the 1990s: you're comprehensively wrong. Consider resetting the "tptacek is always full of shit" bit that is obviously stuck in your brain.
I'm not mischaracterizing tptacek's comment. Nor am I suggesting that there were no bad actors.
tptacek said: "The "hackers" FD's moderator is talking about are the ones I'm talking about.", those being "teenagers breaking into phone switches and harassing people, buying Pantera CDs on stolen credit cards, stealing ESNs from other people's phones to make calls on someone else's bill, and rm'ing Unix boxes".
Obviously, this is not who the FD moderator was talking about, making tptacek's comment unfair.
What's that a reference to?
http://www.ritholtz.com/blog/2014/03/dealbook-misunderstands...
Not to mention the scum like Angelo Mozillo who gave us the financial crisis.
It's at best trying to compare a painter that does portraits to a painter that paints automobiles. Both require skills, but in completely different areas.
http://www.reddit.com/r/netsec/comments/20sxd2/full_disclosu...
this is what a hacker stands for https://w2.eff.org/Censorship/Internet_censorship_bills/barl...
http://seclists.org/fulldisclosure/2014/Mar/170
http://seclists.org/fulldisclosure/2014/Mar/294
http://seclists.org/fulldisclosure/2014/Mar/291
http://seclists.org/fulldisclosure/2014/Mar/286
http://seclists.org/fulldisclosure/2014/Mar/298
And a full email exchange: http://seclists.org/fulldisclosure/2014/Mar/index.html#123
My personal favourite (in a positive way): http://seclists.org/fulldisclosure/2014/Mar/160
http://seclists.org/fulldisclosure/2014/Mar/298
It seems that one guy not only trolled the list but also he either created new identities for more trolling or managed to attract more trolls as bad as he. The guy also appears to deeply believe he's right.
It's still not fully clear to me if he is also the person thus described by the list maintainer:
"I always assumed that the turning point would be a sweeping request for large-scale deletion of information that some vendor or other had taken exception to. I never imagined that request might come from a researcher within the 'community' itself (and I use that word loosely in modern times)."
As you said yourself, this is just the final straw.
People seem to believe that happened because vulnerabilities started to obtain a market value, but:
* The serious high-end memory corruption vulnerabilities were (a) more common and (b) much simpler at FD's inception, making them more amenable to posting on a list; in 2014, a high-end vulnerability is likely to be complex enough to merit in-depth consideration on a blog instead.
* Table-stakes XSS vulnerabilities also tend to get written up in blogs (where they help establish a track record for researchers whose future employers aren't going to trawl through FD looking for them), and when they get bought, get bought by bug bounties. It is hard to argue that bug bounties are a bad thing; nobody benefits from a web vulnerability in a SaaS product other than the operator of the SaaS product.
Full disclosure is a lightly moderated security mailing
list generally used for discussion about information
security and disclosure of vulnerabilities. The list
was created on 9 July 2002 by Len Rose and is
administered by John Cartwright.
The wikipage goes on to list some notable zero-day vulnerabilities. About Full-Disclosure
Unlike bugtraq, this list serves no one except the list members themselves
We don't believe in security by obscurity, and as far as we know, full
disclosure is the only way to ensure that everyone, not just the insiders
have access to the information we need to survive.
We will try to operate this list without moderation, as we feel moderation
is an impediment to communication.
Any information pertaining to vulnerabilities is acceptable, for instance
announcement and discussion thereof, exploit techniques and code, related
tools and papers, and other useful information.
and, forebodingly: Politics should be avoided at all costs.
There's also the original announcement on the SuSE Linux security mailing list[2] and a follow-up by Mr Cartwright with some further rationale[3].[0] https://web.archive.org/web/20050306210635/http://lists.nets...
[1] https://web.archive.org/web/20041205194605/http://lists.nets...
[2] http://marc.info/?l=suse-security&m=102639105014466&w=2
[3] http://marc.info/?l=full-disclosure&m=102965261426089&w=2
The ledger could provide some assurances that others have had access to a given set of messages, but that really only helps with the boring sort of arguments.
I feel like everyone wants to hate moderation but it's one of those things, that when used correctly, make a community good.
I'm on several mailing lists that have grown significantly over 3-7 years. I, along with most other founding members, left lists that didn't have any moderation as they inevitably grew into a community similar to what's described in this announcement.
But the mailing lists/forums that had moderate moderation, removing furry porn for example, have continued to grow and continue their initial cause. Good moderation is not censorship, I would even say that people disrupting the core purpose of a community censor more than a good moderator by burying worthwhile content below shit posts.
It is unfortunate that HN is not numbered among those sites.
Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.
The techniques they detail all amount to an admission that Tor itself is still quite difficult for the NSA to de-anonymize at scale. They resort to exploits against browsers instead, which is far less scalable and far more risky.
According to Snowden, the NSA doesn't want to waste valuable vulnerabilities on low-value targets (since this risks discovery and disclosure, making the vulnerability useless in the future).
So they can't do mass surveillance of Tor, and can only de-anonymize targeted individuals under optimal conditions.
For example, you have done an experiment below of posting comments through tor using the newly-created account "throughtor": https://news.ycombinator.com/threads?id=throughtor
If you turn on "showdead" in your profile, you'll see that account has a bunch of dead comments. Those comments are dead because the "throughtor" account is less than two weeks old, so HN's system automatically kills them since they're posted through tor. Once two weeks elapse, you'll be able to post comments and they won't be struck down. (Two weeks is the time it takes for the "new account" status to wear off.)
This is a spam prevention technique, and it's necessary in order to drastically reduce the amount of work moderators have to do to filter spam.
So, anyone who wants to post anonymously on HN should open up Tor Browser and create an account right now, and save it for a rainy day sometime in the future.
Remember not to use the same password as your regular HN account, because you'll give your identity away if you do. In addition to the fact that there's nothing stopping any server from logging every password across every service, HN also stores passwords as unsalted SHA-1, so two identical passwords on two different HN accounts will be stored as the same hash in the database, making it trivial to detect your real identity.
At least, unsalted SHA-1 was the case as of arc3.1, which is now several years old. Kogir probably changed it to something more sane in the meantime. But I highly doubt anyone will be able to break into HN's server running BSD anyway, so the unsalted SHA-1 isn't really a concern. This is just a reminder that every piece of information you provide is a piece of information that can be used to determine your identity.
And if you use this information to create more work for HN's operators, then I will ssh into your macbook and scare the crap out of you in the middle of the night by setting your volume to 100% and using text-to-speech. But seriously, don't be lame. It's valuable that we are permitted any anonymity at all.
It didn't get much traction. (I can understand why bitcointalk.org is staying where they are. It was when theymos was openly asking what to do with all the donated BTC.)
I would, however, be happy to join a public github repo if there's serious interest.
Also, is there a provable way to generate a public bitcoin address without learning the private key? As a way to keep it fair.
However, there are some implementation issues that need to be resolved, e.g. on github.
As a newcomer I'm not really sure what John's referring to, though. Too bad...
One of the biggest drivers of cash into information security hires is government regulation. Otherwise, a lot of these companies could give a shit if they lose private data.
Enter the information security specialist who has no fucking clue how to program or do anything remotely technical. They went out and got their CISSP cert, and now they provide a legal shield to the corporation or government office that hires them. Their very presence provides the security theater needed to protect their employer from being sued for not providing the necessary security.
If you are a CISSP on here, the fact that you're on this site means you are in the minority of your loser poser peers. You probably hate these posers as much as I do.
Other than that though, carry on.
What's stopping such communities from going "underground", i.e. to some darknet where anonymity and protection from some of these hassles still exists?
Principle? The whole point of FD was for these discussions to happen in the open.
Not heard the quote before; thank you.
Besides Bugtraq what mailing lists security wise do you follow?
EDIT: Or what other general means by Twitter, Websites, Databases, Blogs etc. do you recommend?
But it's probably easier and more convenient to subscribe for announce mailiing lists for software you're using. Unless you can turn off affected services or scramble and patch before maintainers.
Can't help but be a little optimistic, at least the "Google Vulnerability with PoC" youtube-upload trollfest chain of emails is done flooding my inbox this month :D
Spam, trolls and politics are not new, but legal threats and DoS attacks I didn't expect to be problems.
Often when things are at a really bad state its in the public interest to make sure these issues get fixed rather than brushed under the carpet. Hence it gets posted on various sec ML lists to ramp up pressure.
In the past I've given lots of information about requests to moderate or otherwise remove content from forums I run.
Then I was hit with a cease and desist, and again provided transparency of it. The very predictable Streisand effect kicked in, and then I was hit with a harassment case too (for disclosing the details even though I knew it would likely trigger Streisand).
It was all resolved quite peacefully, but one fire-fights these things reasonably over the years and get to learn that the other party is usually not being reasonable. You can either result in escalation, or you can calm things down.
It's a lot easier to pick the option that calms things down if it's available to you. And in case above, that was apocalyptic, to close the list without disclosing detail behind it.
The last straw really breaks the camels' back. Once broken, it's not getting up to fight on. Life is too short.
Receiving legal threats (either real of vague promises of one), being accused of censorship and denying someone's right to freedom of speech (and having to explain that's not how free speech works), cleaning up spam and trying to sort out fights between users really wears you down after a while.
A lot of work goes on behind the scenes of running a 'community' and it can be stressful, draining and generally not fun.
You are free to try to step in to the gap created by the closure of this list and run a replacement service. I'm sure someone will.
If I add one of the latest in the series of my own experiences. Once upon a time someone wanted to scam me on a website deal. We figured out who it was (it was easy, he was the owner of the domain, paid for the hosting etc.) and published the details (we were not the first, he's quite a known scammer around here, we found numerous blogposts about him). He was even featured in a local newspaper. Fast forward 5 or so years and I get a Cease and Desist letter from him (or something looking like that) that the information in my blog post is not accurate and he will sue me. I quickly see that google doesen't bring much about him nowadays, in part to people not caring for their blogs/doing redesigns and in part of him sending out "scary" letters. Of course I could fight it, I had a lot of concrete (I was told court grade by some lawyer acquaintances) proofs. But was it worth my time? My effort? My psych? No. I redacted the blog post and let it be. I don't feel good about it, because that means he will try to scam people that could'we been warned from my post. But I wagered it and left it all behind.
EDIT: grammar n'stuff
And, the better your case, the more soul-draining it is. I would imagine that it is easy to comply when one knows he is in the wrong. But, when one feels strongly about the cause and is advised that he has an excellent case, then capitulation feels like being bullied and extorted into compromising one's principles. This, even when it is frequently the most prudent thing to do.
So, one is left with the sad choice of either compromising his principles or fighting indefinitely at significant cost in time, money, and emotional energy.
Once you proceed past the "first sign of conflict", you will quickly sink a lot of cash. You don't get a refund if you later decide to stop, nor any other credit. That money is gone and either you keep going until you a.) win (or lose) a protracted, costly battle; b.) bankrupt your cash, energy, or will; or c.) find an opportunity to settle and stop the bleeding. By then, the damage is done.
So, if you decide to proceed, then you are signing up for significant cost and a ride for which you have limited control. They will keep throwing stuff at you to entangle and frustrate you. If you take the suit as far as discovery, then you can get into the high 6-figure or even 7-figure range before you know it.
And, before you get to discovery, the motions, counter-motions, and other pleadings can easily get you to six figures within a few short months or less (depending on the complexity of the case).
If you are a small business, it can be a non-starter, especially when the plaintiff is a much larger (and hostile) company. I've been through it personally and I decided not to "capitulate at the first sign of conflict". I was pissed, they were wrong, I wouldn't be bullied, etc. So, I fought it.
We handily beat them back on the initial injunction they were seeking. Based on the merit, we knew we'd win that easily. Still, it cost me ~$20K to actually do it. It doesn't matter how weak their case is. They can make you bleed to prove it. The standard for having the suit labeled frivolous is extraordinarily high and you almost assuredly will not recover your legal fees.
We kept fighting, using some of the foundation (research, etc.) laid during the injunction battle to reduce costs. Still, by the time, we reached the mandatory (in the state of CA) settlement conference (where we decided to settle), we were out over $100K. So, that was the price of "not capitulating at the first sign of conflict". Of course, we didn't have to concede everything they initially demanded, but that small victory felt a bit Pyrrhic.
And, none of this cost includes the time, mental energy, and stress involved. If you are running a small business, you likely don't have time/energy for it. So, beyond literally bankrupting you, it can damage your business (perhaps irreparably) in other ways.
Source: I've run a public forum with anonymous posting for about 10 years and get regular legal/removal threats. Had four in one day the other week. None have ever proceeded beyond a threatening letter from a lawyer and most don't get past "I've printed this out and I'm taking it to my lawyer."
Seriously, use 30 seconds to browse, ie http://marc.info/?l=full-disclosure&r=1&b=201403&w=2
Notice 144 posts about "Google vulnerabilities with PoC"?