Hacker News new | past | comments | ask | show | jobs | submit login
Walk a mile in Egor’s shoes (bradlanders.com)
2 points by bradleyland on March 5, 2012 | hide | past | favorite | 2 comments



a couple of things. first, egor's actions are a good example of the "full disclosure" debate that's been around for a long, long time. some pointers:

http://www.schneier.com/crypto-gram-0111.html

http://www.schneier.com/blog/archives/2007/01/debating_full_...

http://www.schneier.com/blog/archives/2011/12/recent_develop...

secondly, egor's motives are NOT clear, you're assuming certain motives. while he demonstrated some effort at trying to contact github to get their attention and a modicum of restraint in his demonstration of the bug, don't assume his complete set of motives are pure and goodly. he has, after all, gotten a truckload of attention over this. fully disclosing an issue benefits the reporter quite a bit, often more than anyone else (attackers included). it would not surprise me if he had this in mind when he acted the way he did.

before you encourage others to walk a mile in egor's shoes, you should probably figure out what kind of footwear he's wearing. you may be surprised.


It's not so much that I believe his motives were benevolent, but that I know how conflicted one can feel when you A) know about a serious vulnerability, and B) don't feel that it was taken seriously.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: