MacGyver101
Joined: 21 Jun 2006
Posts: 87
Location: Toronto, Canada
Posted: Thu Aug 30, 2007 11:43 pm Post subject:
I respect your opinion, but I think that you'll find many people on these forums are of a slightly different mindset when it comes to disclosure. For whatever value it brings, let me try to explain my own perspective...
I choose to participate on these forums exactly because there is a division between the "public" and "advanced" discussions. (And, to be clear, I do not yet have "advanced" access.) As you note, there many other places -- and several competing sites -- that take an "anything goes" approach to disclosure. I have no problem with that for issues like software bugs (e.g., your example of Defcon), because it can allow people to better protect themselves. Locks, however, are not like software... and this is where the Defcon analogy falls down.
There is no "Check for Updates from Schlage" button on my house that I can press to automatically patch the locks on my front and back doors every few days... and that is one of the major differences between software security and lock security. I think that the rate of disclosure should be tempered by the rate at which people update their technology. People are exposed to unpatched lock exploits for much, much longer than they are exposed to unpatched software exploits. If I am permitted to join the discussions in the "advanced" forums, I would prefer that those discussions are not shared with every 12-year-old who has access to Google. That's my choice, and it's why I choose to participate in this particular on-line community.
For what it's worth, I hope that helps?
-----------------------------------------------------------------------------------
Since I couldn't reply to your reply (locked) I had to repost.
My Defcon analogy didn't fall down, quite the opposite, I've watched seminars from the past years on YouTube and other video posting websites and on more than one occasion a reporter had asked the question "what do you plan on achieving by letting all these people watch you pick a lock etc." to which the speaker replied. "The crooks and thieves already know all of this and more, by us at Defcon showing and explainig how lock picking works and with some practice how easy it is, we hope to better protect the public. If you know where the vulnerabilities are you are more knowledgeable to better protect yourself and take a proactive approach to better safeguard your home".
And to reply to your "12 year old getting this info". My answer is go to http://youtube.com/watch?v=C5fLgxqWvJQ here you will watch an 11yr old girl using key bumping at Defcon. If the people at Defcon feel it's okay why can't you. Don't worry about the 12 year old bullies in your neighbourhood, worry about the crackheads here in Toronto that will throw a brick through your window and steel your microwave or LCD TV.
And to finish off, if you admit "advanced" information is tolerated on other websites and is readily available.........if someone wants to know, they will find out so although the fight is valiant, the struggle is futile.
"Not ignorance, but ignorance of ignorance, is the death of knowledge", Alfred North Whitehead.