Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> It's almost like CiPHPerCoder is personally offended that some joe random developer hasn't heard about some obscure CVE CiPHPerCoder was involved with, or that they didn't handle it like he would like. "Do you know who I am!?"

Except this isn't "some joe random developer", this is software created by and for the US government, which is featured on code.gov.

I'd expect them to take security seriously and apply all upstream security patches immediately, not sit on them for years after they've been resolved.

Anything but that is sheer negligence. What else hasn't been updated which contains vulnerabilities that do affect them?

> The initial issue was he came here and ranted about it, instead of pointing it out to the projects.

That's what joepie91 was trying to explain to you.

> Eventually he "gave in" and reported it to a single project, but took this holier-than-thou tone and was aggressive the entire time. That's ridiculous.

Would you rather I do that or not report it to them at all? Choose only one. If I'm going to do it, I'm not going to do it your way. You can if you want.

Personally, I'd rather not report bugs at all. Until you've reported vulnerabilities to two or three dozen different projects, this might not mean much, but: It burns you out to keep reporting the same flaws to different projects.

Having developers respond to security risks with an air of entitlement just turns up the heat on the burn-out engine.

The first response to my comment here was

  You should send in a pull request, or file a bug report in the repo.
Pay attention to the order of operations here. The "should" is immediately associated with a large amount of unpaid work, with an alternative that would also be a large amount of unpaid work disguised as a hypothetically smaller amount of effort. But as others have stated: It's not.

> It's not surprising CiPHPerCoder got the reaction he did - it is, however, surprising he decided to do all this under his company's name.

Even if I had remembered to switch Github accounts, people would still associate it with my employer anyway. Kind of a moot point, really.

I gave you what you asked for. Next time, maybe don't tell people what they should do? It's rude to bark orders like that, and it won't get the result you want.



Perhaps if you didn't act like a jackass when reporting bugs, you'd have better interactions, and get less of the "burn out" feeling you're describing.

And next time you decide to put on a show, consider not doing it under your company name.

You're forgetting this arrogant display is here for all to witness, including folks who may (or may not, now) want to contract your company in the future. You also seem to forget the very folks behind code.gov are the same ones that influence who gets contracted with the government...

The people working on code.gov and all of the repositories are truly doing something great. Code has been in the federal government for at least 60 years, probably longer - and this is the first time something like code.gov has been produced. It's an amazing effort, and it's surely not easy to effect change like this at the federal level.

The open source initiative will help increase code quality at the federal level, as well as encourage less duplication of efforts (different agencies likely solve similar or the same problems very often). It also encourages a baseline standard of code and organization. This is a fantastic beginning!

Next time, a simple "Hey, did you guys know about CVE-2015-2171? You may have some vulnerabilities." is all that's needed. Instead, you let everyone know you were in a fit of rage - how dare someone suggest you comment on an issue you brought up!

We need to encourage and support these efforts, not shit all over them.

In short, don't be an ass... please.


> You're forgetting this arrogant display is here for all to witness, including folks who may (or may not, now) want to contract your company in the future. You also seem to forget the very folks behind code.gov are the same ones that influence who gets contracted with the government...

If you base your "security talent" hiring decisions the same way you approach "contract customer service representative decisions, you'll end up with very pleasant people who don't know jack shit about security. Which would explain a lot of the results we're seeing. So you might be right.

If anyone is reading this thread and wants their software to be actually secure-- no sugar-coating or letting bad decisions happen-- get in touch. :)

> The people working on code.gov and all of the repositories are truly doing something great. Code has been in the federal government for at least 60 years, probably longer - and this is the first time something like code.gov has been produced. It's an amazing effort, and it's surely not easy to effect change like this at the federal level.

For once, we are in agreement.

> Next time, a simple "Hey, did you guys know about CVE-2015-2171? You may have some vulnerabilities." is all that's needed.

OK, why didn't you do that then?

It's so easy to tell others what to do, when you have no skin in the game. What will you do next time?

  - Tell the other person what to do.
  - Do it yourself, because it clearly matters to you.
> We need to encourage and support these efforts, not shit all over them.

> In short, don't be an ass... please.

I won't be an ass if and only if folks aren't making demands of how I spend my leisure time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: