I agree though. Hard to argue that this particular security issue needed any extra attention in order to get it fixed.
I agree though. Hard to argue that this particular security issue needed any extra attention in order to get it fixed.
But I don't get the leap from "IDS vendors suck" to "I made a command-line tool so any idiot can suck down private keys from a server." If the idea was to show that the IDS rules sucked, then just release a slightly different version of the previous heartbleed testers that gets around it.
But that's not as much fun.
100% true. The argument Dan and others are trying to make is there are a lot of people caught in the cross-fire who have nothing to do with IDS-vendors claims.
If you went back in time two years and fixed the Heartbleed bug, no one would be writing newspaper articles about you.
This is hardly something isolated to the security industry. It's human nature. Some person sealing a hole is nowhere near as attention-gathering as a hole leading to a catastrophic flood due to no one realizing that it needs to be sealed.
The potential for something bad to happen doesn't raise anywhere near as much eyebrows as the bad thing actually happening, especially for something as invisible to the average person as a software vulnerability.