Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hiding our heads in the sand only means that the vulnerabilities will not be fixed and that only especially crafty attackers (i.e. the most dangerous ones) can exploit them. We need more openness, not security based on someone's feelings of morality.



How does Shodan promote openness? Anyone who wants to scan their own network can already do so with paid for and free tools. What this service does is, it scans your network whether you want it or not, then allows others to search for vulnerable hosts. It is a script kiddie wet dream come true service.

Continuing my "trying door handles on cars or houses" analogy imagine there is a service that has people walking from car to car and from house to house covering whole cities. Then once it compiled a database of which houses/flats/cars tend to be unlocked it made a business out of selling access to that DB. Would you have no moral reservations about that?

Almost everyone is for openness in matters of vulnerabilities in software so companies are forced to fix them, but still most 0day researches give heads up to the companies and shortly later mailing lists about the vulnerabilities they discover before they openly publish all the details including an example exploit. Therefore openness has widely accepted limits. Making a business out of selling information about third parties that are vulnerable is way past those limits.


If it forces people to invest in securing their systems, it will have already done more good than whining about morality.


>If it forces people to invest in securing their systems, it will have already done more good than whining about morality

It'll not force people to do anything, unless by forcing them you mean it will send attackers their way, they will get pwned, their systems screwed and they learn their lesson the hard way. You may well be in favour of this kind of mass education of inept-admins, but I'm not.

As for "whining" about morality, you know humans invented and use it when making decisions because it is useful in preventing conflict. What happens if companies don't give a fuck about morality of their actions? People hurt by them use forceful means to "make things right" in their mind.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: