1,568 karma · joined April 23, 2014
https://cretezy.com
Work @ Lyft, all opinions my own
Netflix can be more stable, and can save on bandwidth in their own DCs.
ISP can save a lot of egress bandwidth by having Netflix inside their infrastructure.
I would be surprised if any of the parties payed. It's a great strategy to have the ISPs on board with this
Fingerprint are not very secure, but as this is meant to be only for physical access with the password, it's much better than before.
The vendor can also usually request an extension, as per the Project Zero guidelines, of I believe 1 month if they confirm to be actively working on a patch.
The goal of responsible disclosure is to help the vendor and their users' be more secure, so having a policy that is balence between the two is important to let the vendor fix it, and to not let the users be possibly hacked
- Researcher finds bug
- Researcher discloses to vendor
- Vendor fixes (or not)
- Researcher discloses bug publically once vendor has fixed, or after X time (whichever is first)
This is roughly how Project Zero goes, and it's a good mix between giving the vendor the opportinity to fix it and deploy the update before it gets exploited.
It's very naive to assume that bugs can be fixed before others can exploit them. Bugs take time to fix, and the process takes time, especially when dealing with large enterprises.
Edit: Looked at the network requests, it's not images. It's returning config files with the information to emulate it. https://download.lenovo.com/bsco/schemas/ThinkPad%20X1%20Car...
Not an expert though, might be wrong but the text makes it pretty clear