pull down to refresh

Rob seems like a pretty cool guy, but he is also really, really good at marketing

I'm so tired of the "we found vulns, but we're not gonna tell you anything except we found it" gimmick

Isn't responsible disclosure a thing? I guess he could just not mention finding anything, but I think some of what he is trying to do here (for good or I'll) is capitalize on the energy around Coldcard and maybe there really could be a useful group effort here that results in a net win for people.

reply

Yeah I don't see how any of what he's doing is bad. He's been a good, knowledgeable source of information during this and I'm happy someone is doing what he's doing. If Anchorwatch gets business because of it that doesn't bother me in the slightest.

reply

It's not that I'm saying he's doing anything bad. It's that I'm tired of listening to words and unverified claims. Believing unverified claims is what got us here.

reply

GOOD! Please don't disclose whatever you find while you verify before a fix is released, or steal coin. Thanks!

reply

How should he do this? Just try to privately contact the developers.

reply

No dev is going to tell you how many vulns are in the pipeline before they are patched and (I guess this has become optional now) rolled out.

reply

Right. A vague statement like this makes sense to me because it communicates to people that there’s a reasonable possibility that something’s wrong with their setup without putting them at risk by pointing attacks towards them.

reply

Exactly, though before the "responsible disclosure" process meant you completely stfu in public until it is patched. I do think that there is no point anymore. Even Linux kernel security people are arguing that it's better to say what's wrong straight away (and offer a mitigation) than to have an embargo.

Not everything will have a mitigation though.

reply