I think the only misleading part of this situation is your naive and self-centered definition of "trust", and the assumption that so many others think similarly enough that they need to be warned.
I trust a business to fulfill their obligations as stated in writing for the money paid. I do not trust them in any other way. Nobody should "trust" or depend on undefined behavior. Common sense can only ever be as common as you expect.
This was a potential customer reporting a result of an audit of a tool they are evaluating. This is frequent and normal activity in enterprise deals. Most of the time such reports are not critical vulnerabilities it would things like tenant configuration -what business would like versus what CISO will accept or risk acceptance of the product they are buying with monitoring or other prescription on access restrictions or a DPA and so on.
It would be novel business model to spend ton of money in getting a prospect to late-deal stage where they are ready to do a security audio for you just so that part is "free" .
Most companies wouldn't disclose(to the public) even if it was serious , that is not their job, they will report to internal teams and re-review on fix. Strix.ai has a benefit in doing so as they sell a scanning tool for this purpose so we get to hear of this.
First, you're being petty and just fighting fire with fire. Second, most of this research is fairly trivial.
What you're instead encouraging is a race to the bottom. You're not going to kill off the companies you hate by withholding information. You don't even have that power anyway because by its very nature, security research is not secret. You're really just encouraging pessimistic groupthink and bad faith. This is why businesses can't be more open about their flaws. It's not that they're stupid and incompetent, but that the pitchforks come out. These are the seeds of dystopia.
They would have eventually figured it out, but as an unfortunate incident with an outsized effect. As much as you wish it to be true, even the worst of these incidents will not kill their business. As much as you hate these businesses, their financial momentum will eventually cause the public to depend on them more. There's more at stake here than anyone's personal gain. It's naive to think otherwise.
You're just manifesting broken windows and ignoring litter thinking you're fighting the man. This is straight up ghetto punk ass behavior wearing a white collar.
> You're just manifesting broken windows and ignoring litter thinking you're fighting the man. This is straight up ghetto punk ass behavior wearing a white collar.
are you replying to the right person?
I'm not hating on any business or trying to "kill" any business.
I'm saying serve yourself, not them. if you have say, a 0 day on your hands, do what serves you best.
> I'm saying serve yourself, not them. if you have say, a 0 day on your hands, do what serves you best. is that "ghetto punk ass behavior"?
Yes.
If you have say, managed to find an overlooked passage into an ostensibly high security building, "doing what serves you best" such as selling the information to some thugs, is in fact that kind of behavior.
Phoenix can stay hot at night in the summer. Tonight is a good example. It's 90 all night and won't hit the low of 80 until 7am. This is borderline uninhabitable for many.
If you want the worst of both worlds with that kind of oppressive heat 24/7 and high humidity, take a look at Houston.
I agree that it is to some extent about optics for the cops, but access controls and properly scoped authorization are always problems everywhere in software.
That's not to say we should let any of this slide, but that we should realize it is time we take this aspect of security more seriously. We are living in that future now. Yes, your shitty janky auth scheme is causing real problems right now and yes it sometimes is life or death.
We're missing an entire category of software that manages permissions in more dynamic ways... Meanwhile, about a third of devs out there don't even know or care about the difference between authn and authz.
certainly something we've seen an epic-facepalm on with the huggingface hack. oh your mongo all just uses one static username/password. oh your cross-cluster connection is all one password.
reciprocally though i think the top down securitization of systems with only proper access control has taken out a lot of the grease that used to greatly ease how companies related to the world in really good ways. even when you do get through to support on the phone, there's often such a grim expectation that they will be in no way able to help you, that they don't really have access to information or corporate processes that are going to do anything for you.
we (engineers) look at defined behavior & constraints as secure, safe, good. but i think the informal processes and laxity from the pre-coded world allowed companies to better actually help people and to be good, in important ways. we have to recognize that mechanization is not always a good force too, while also starting to take more seriously too that we often do need more oversight/guards/access-control too. it's paradox, it's duality, but we have to recognize both ends as dangerous.
Yes, I'm saying if we are going to "mechanize" as you say, there are a ton of missing integrations to provide that authorization context. These abuse stories sound like we're far too dependent on a backlog of audits that grows faster than they can be executed (if ever).
We need more dynamic systems that can match the real-world pace that these investigations occur. This doesn't even necessarily mean "automation", and it's not clear whether that would make things worse.
It makes me wonder what other processes are being overlooked, even going way back long before computers. Anyone who has received a simple citation for speeding can attest that it was probably blank or damn near. Apart from the cop not showing up in court, this is a common reason to get it dismissed. We've been normalizing these kinds of failures for much longer than we've had computers involved.
There's a deeper problem here, but we can't keep placing all the blame solely on cops or devs. There has to be a way to fix this. There just have to be other disciplines with similar problems that were resolved without any drama simply because there's less noise and politics in the way.
Is it only fat people who pay extra for more personal space on any other form of transport?
I think there's a stronger argument that if you really don't want huge vehicles, you could at least improve ventilation. Air quality and temperature have a massive psychological effect.
Anecdotally, I think most people were fine with a subcompact back in the day because they weren't so airtight and we used to even have crotch vents. So much comfort has been sacrificed over the years because of autistic designer bullshit like "road noise".
It's why you can hop into an old Toyota truck (far smaller than modern SUVs) and instantly feel at ease and grounded. Fits like an old glove and that was always the point. You get improved road awareness and less highway hypnosis. You don't get that nervous system disconnect between your inputs into the car and the feedback. It feels more like an extension of your body and less like a spaceship or coffin on wheels.
After 10 straight hours of freeway driving across Texas, give me a spaceship on wheels with "autistic bullshit" no road noise, please. Or better yet, something that drives itself. Don't get me wrong, I love a spirited jaunt through the mountains on four or two wheels, but the vehicle for that isn't the vehicle to drive in an almost straight line for 10 (or more!) straight hours.
I don't think the vehicle is going to make a difference at that point. You shouldn't be driving so long without a break anyway!
Thanks for demonstrating the attitude that got us here in the first place, though. In your reply, we have an answer for the rest of the world why americans buy SUVs.
That attitude is a physics problem reflected by culture. El Paso to Houston is a 10 hour drive. it's worse in Africa. Algiers to Marrakesh is a 15 hour drive. Djibouti to Johannesburg is 4.5 days. But Amsterdam to Berlin is only 7 by car/bus/train or 80 minutes by air. Seoul to Pyongyang is only three hours. Theoretically.
The difference in the amount of people who live between those is vast though, and the rest of the world is used to horribly long bus drives, they're just too poor to complain anywhere you or I would frequent. Point is, EV self driving sleeper cabins are going to change the world, though self-driving hot tubs in major cities is liable to come first.
Is this just the same tired old SVG turbulence filter people have been using since forever?
Why would I introduce a "left-pad"-like dependency into my UI? I don't want to depend on these half-assed implementations of UI elements. I want my own or those of a better library and to merely have the sketchy style.
I don't know why you're getting downvoted. You're spot on.
Almost everyone developing their own AI is doomed to fail. I would not be surprised that when the dust settles, Microsoft CoPilot and Google Gemini will be left standing while OpenAI and Anthropic fade away. They will get what they need and then throw them away.
"Embrace, extend, extinguish" is the same playbook for decades, and you can only do that when you make money. Yes, making money still matters and post-capitalism is a big fat lie.
Copilot is part of the enterprise suite, so like everything else Microsoft does in that regard it's never been anything but a roaring success by its own definition.
Of course that's relative to how these kinds of things are used, but it really does get used. It might be the best feature of MS Teams.
Copilot is the cockroach of corporate AI. It ain't going nowhere.
I have similar problems being a passenger in an uber for more than 15 mins. I lose my mind on roadtrips when it's not my turn to drive.
reply