|
Re: Team 548 Einstein Statement
Quote:
Originally Posted by techhelpbb
Starting today it's been 30 days since I sent my first e-mail about this.
6 months is the end of January 2013.
If I follow through with the 6 month process as it stands now I'll be giving the next interloper the perfect window of opportunity for 2013 by publishing in late January. FIRST who might do nothing with the knowledge till then would have little time to react. Worse FIRST will have solidified all their purchases and shipped all the kits of parts.
Suffice it say I'm not thrilled with this. Worse even if I don't point it out then depending on a number of likely factors these exploits will be readily available to any interlopers that we don't know about if they've stumbled on them.
If that's not a house of cards I don't know what is.
So if I publish that information I risk FIRST responding by sanctioning me.
If I don't publish that information who knows if or when it'll get exploited.
For those who get the reference:
'The only way to win is not to play' and unfortunately I don't mean looking for security problem.
|
You took the number 6 months entirely too seriously. I quite literally pulled that number out of thin air just to let people know that 2 weeks is NOT an appropriate period of time. Obviously publishing just before another round of competitions might not be good. But I was assuming that if a person is intelligent enough to discover the vulnerability and be wise enough to know how to go about exposing it they would have SOME common sense. I guess that's asking too much from people though.
__________________
.
Last edited by Andrew Schreiber : 21-08-2012 at 15:18.
|