pull down to refresh
Isn't responsible disclosure a thing? I guess he could just not mention finding anything, but I think some of what he is trying to do here (for good or I'll) is capitalize on the energy around Coldcard and maybe there really could be a useful group effort here that results in a net win for people.
Yeah I don't see how any of what he's doing is bad. He's been a good, knowledgeable source of information during this and I'm happy someone is doing what he's doing. If Anchorwatch gets business because of it that doesn't bother me in the slightest.
It's not that I'm saying he's doing anything bad. It's that I'm tired of listening to words and unverified claims. Believing unverified claims is what got us here.
How should he do this? Just try to privately contact the developers.
Right. A vague statement like this makes sense to me because it communicates to people that there’s a reasonable possibility that something’s wrong with their setup without putting them at risk by pointing attacks towards them.
Exactly, though before the "responsible disclosure" process meant you completely stfu in public until it is patched. I do think that there is no point anymore. Even Linux kernel security people are arguing that it's better to say what's wrong straight away (and offer a mitigation) than to have an embargo.
Not everything will have a mitigation though.
I'm so tired of the "we found vulns, but we're not gonna tell you anything except we found it" gimmick