best of ilx administator emails

Message Bookmarked
Bookmark Removed
post plz

JW, Tuesday, 6 March 2007 21:37 (eighteen years ago)

[Dere Stet. Pls to not bother to write me a lengthy explanation next time.]

(Stet edit. That's essentially what was here -- an email from me to Jon, after I took down the old site when he fucked with it)

JW, Tuesday, 6 March 2007 21:39 (eighteen years ago)

That would fix that hole. What about all the others?

You know how security disclosures (should) work. You find a hole, you
tell the responsible people, and if they don't fix it in a given
amount of time, you go public. You don't exploit it then offer a
solution.

ILX is locked because what is to stop you trying to find another hole
and then exploiting it?

A

JW, Tuesday, 6 March 2007 21:39 (eighteen years ago)

i tire of this crusade :(

elmo argonaut, Tuesday, 6 March 2007 21:41 (eighteen years ago)

Andrew G
to me

show details
4/3/06
I am going to fix ILX good god damn it.
- Show quoted text -

JW, Tuesday, 6 March 2007 21:42 (eighteen years ago)

alternate title: my e-dick is SO BIG!

sleep, Tuesday, 6 March 2007 21:45 (eighteen years ago)

look everyone look

sleep, Tuesday, 6 March 2007 21:46 (eighteen years ago)

vic OTM, jon plz to aim your pissing at TOMBOT

elmo argonaut, Tuesday, 6 March 2007 21:47 (eighteen years ago)

It does look
as if you tried to exploit that one (from your work computer, ffs!) on
Jan 17, though.


!

JW, Tuesday, 6 March 2007 21:47 (eighteen years ago)

i felt like this once too. then i took a xanax and the pain went away

chimera, Tuesday, 6 March 2007 21:49 (eighteen years ago)

tombot only knows CSS though so he is blameless in all this!

JW, Tuesday, 6 March 2007 21:49 (eighteen years ago)

http://img129.imageshack.us/img129/1734/ilxsz7.jpg

jaxon, Tuesday, 6 March 2007 21:49 (eighteen years ago)

JESUS CHRIST JON GO GET A BLOW JOB OR SOMETHING ALREADY!!!

the schef (adam schefter ha ha), Tuesday, 6 March 2007 21:53 (eighteen years ago)

Jaxon's photoshop skills are top notch!

jessie monster, Tuesday, 6 March 2007 21:55 (eighteen years ago)

I'M QUITTING SMOKING TODAY :(

JW, Tuesday, 6 March 2007 22:01 (eighteen years ago)

LOL, u used guy's real name on internet.

nickalicious, Tuesday, 6 March 2007 22:02 (eighteen years ago)

THAT WON'T BRING HIM BACK, YOU'VE GOT TO FORGIVE YOURSELF BEFORE THE HEALING CAN BEGIN

ghost rider, Tuesday, 6 March 2007 22:03 (eighteen years ago)

I am going to fix ILX good god damn it.

JW, Wednesday, 7 March 2007 00:44 (eighteen years ago)

[i]

JW, Wednesday, 7 March 2007 00:45 (eighteen years ago)

I'M QUITTING SMOKING TODAY :(

I don't know if this will work, but I think part of it can be eased by taking deep breaths. I don't know about breaking the actual chemical addiction, but I've always thought that part of it was being accustomed to the physical phenomenon. I think your body wants the heaviness in the lungs and a lot of air (deep breath) can provide that? Temporary relief, maybe, but all you have to do is take another fucking deep breath of air when it comes back maybe?

Tim Ellison, Wednesday, 7 March 2007 01:24 (eighteen years ago)

JW, WINNING OVER HEARTS AND MINDS EVERYWHERE

sanskrit, Wednesday, 7 March 2007 01:25 (eighteen years ago)

Also sexual release might help!

Tim Ellison, Wednesday, 7 March 2007 01:26 (eighteen years ago)

iirc jon swizzles his weenus frequently as the tides lap the pier

remy bean, Wednesday, 7 March 2007 01:48 (eighteen years ago)

http://www.williamsforkids.com/images/usflag_top.jpg

remy bean, Wednesday, 7 March 2007 03:33 (eighteen years ago)

http://www.williamsforkids.com/images/JOIN/top.jpg

remy bean, Wednesday, 7 March 2007 03:33 (eighteen years ago)

crepey!

tehresa, Wednesday, 7 March 2007 03:40 (eighteen years ago)

By Marcus J. Ranum

Can we speak frankly about "vulnerability disclosure" now? Can we, please? It’s long past time. More than a decade into the process, can anyone say security has improved?

Back in the mid-1990s, when the vulnerability disclosure economy was starting to take shape, I was one of a small handful of security practitioners who was trying hard to apply the brakes against what we saw as a dangerous trend. Unfortunately, at that time, the security industry was not yet mature enough for customers to understand that they were being sold a dangerous bill of goods. For longer than a decade, we’ve lived under the mob rule, where for some security consultants and companies, "marketing" has been replaced by "splashily announcing holes in commercial products to get 20 seconds of fame on CNN." What’s amazing about the disclosure game is not that it’s been tolerated for so long, but that it worked at all. (See Schneier: Full Disclosure of Security Vulnerabilities a ’Damned Good Idea’.)

Do you remember the original premise of the disclosure game? By publicly announcing vulnerabilities in products we will force the vendors to be more responsive in fixing them, and security will be better. Remember that one? Tell me, dear reader, after 10 years of flash-alerts, rushed patch cycles and zero-day attacks, do you think security has gotten better? (See Microsoft: Responsible Vulnerability Disclosure Protects Users.)

I think there are a few places where we can see signs of improvement. I know that Microsoft, Oracle and others have spent huge amounts of money improving the security of their software. Never mind the fact that 99.99 percent of the computer users in the world would rather they had spent that money making their software cheaper or faster, I suppose it’s a great thing to see that software security is being taken seriously. Security has gotten more expensive. But do you think security has gotten better?

From where I sit, it looks like the vulnerability rate is pretty much a constant. If the proponents of disclosure were right, their stated objective—browbeating the vendors into making their products better—would have been accomplished years ago. But we’re speaking frankly, here, aren’t we? So, as one adult to another, let me tell you why it won’t work: because it was never about making software better. In fact, it was never about making your security better. That’s right. Now that we can look back at 10 years of what disclosure has brought us, it’s brought us…well, nothing much. Nothing much, that is, except a grey-market economy in exploits, where independent "vulnerability researchers" attempt to cash in by finding new attacks that they can sell to security companies or spyware manufacturers—whichever bids higher. Nothing much unless you count the massive amounts of "free" marketing exposure for companies that trade in exploits. The sad part about it all is that they’ve managed to convince you they’re doing you a favor. It looks like a pretty expensive-looking "favor" to me!

Back when the Internet security bubble started, I offered a litmus test for practitioners. Simply put: You’re either part of the solution, or you’re part of the problem. You’re writing the next firewall or secure application or working to improve some site’s security. Or you’re part of the problem: You’re looking for the next hole in Oracle that’ll get you two minutes on CNN, or you’re getting ready to announce a clever new way rootkits can evade detection from security tools, or you’re devising the next denial-of-service attack, etc. The state of ethics in the computer security industry is pathetic; it’s on par with where medicine was in the 1820s—except that some of the snake-oil salesmen in the 1820s actually believed in their products.

At this point in the history of security, the disclosure economy has been in place long enough that some of the new entrants to the field think that’s the way it’s always been—I’ve run into second-generation "true believers" who really think vulnerability disclosure is all about making software better. Guys, I think it’s time to hang up that ideology; it’s obviously not true. If it was going to help, it would have showed some signs of helping by now. So let’s be frank, shall we? Those of you who are playing the disclosure game are just playing for your two minutes of fame: You’re not making software better. Sure, some of you work for consultancies and startups, and it saves you a ton of money by not having to have a marketing budget, but isn’t shouting "fire!" in a crowded theater so…um, ’90s? I know that the typical security customer is (to you) an unsophisticated rube, but that does not justify you placing them at increased risk just so you can publish a new signature for your pen-testing tool or get your funny-haired "chief hacking officer" on CNN one more time. I have news for you: Most of the computer users on the planet wish you’d find some other use for your talents—something that actually does help.

Computer security needs to grow the hell up, and needs to do it pretty quickly. It seems that virtually every aspect of life is becoming increasingly computerized and exposed to online attack. The problem is getting more significant the longer we wait to deal with it, but the early history of computer security has been a massive disappointment to all of us: huge amounts of money spent with relatively little improvement to show for it. One of the reasons is that a huge amount of that effort has been wasted, barking up the wrong tree. Unfortunately, if you look at the last 10 years of security, it’s a litany of "one step forward, one step back," thanks in part to the vulnerability pimps, parasites and snake-oil salesmen who flocked into the industry when they smelled money and a chance to get some attention. At this point, they’re so deeply entrenched and vested that they’re here to stay, unless the industry as a whole turns away from rewarding bad behavior. If you’re a customer or end user, you can see how well disclosure worked to improve your security over the last decade. Let me be frank: It’s up to you.

TOMBOT, Wednesday, 7 March 2007 16:02 (eighteen years ago)

http://www.hyperleap.nl/bioscoop/library/show_image_bio1.php?ID=1195&max_w=160&max_h=1000

the schef (adam schefter ha ha), Wednesday, 7 March 2007 16:10 (eighteen years ago)

http://imagecache2.allposters.com/images/pic/153/1025184~The-War-of-the-Roses-Posters.jpg

ghost rider, Wednesday, 7 March 2007 16:12 (eighteen years ago)

http://quake.swe.net/~drago/covers/face_off_special_edition.jpg

sanskrit, Wednesday, 7 March 2007 16:18 (eighteen years ago)

Quitting smoking going ok

JW, Wednesday, 7 March 2007 16:20 (eighteen years ago)

i want to take his face.......OFF

gbx, Wednesday, 7 March 2007 16:21 (eighteen years ago)

None of you guys can find an animated gif of bill pullman turning into balthazar getty = you are all receiving a poor performance review for the quarter

TOMBOT, Wednesday, 7 March 2007 16:24 (eighteen years ago)

http://www.jewishflicks.com/images/broadcast%20news.jpg

the schef (adam schefter ha ha), Wednesday, 7 March 2007 16:35 (eighteen years ago)

i nominate the complete works of psychotically paranoid aepn flux forum mod barb.e

moonship journey to baja, Thursday, 8 March 2007 18:56 (eighteen years ago)

HEY GUYS DID YOU HEAR JON IS QUITTING SMOKING?

chaki, Thursday, 8 March 2007 20:06 (eighteen years ago)

that explains why he got fat

the schef (adam schefter ha ha), Thursday, 8 March 2007 20:16 (eighteen years ago)

wait, JON IS FAT?!?!?

chicago kevin, Thursday, 8 March 2007 20:17 (eighteen years ago)

i am eating chips

JW, Thursday, 8 March 2007 20:21 (eighteen years ago)

http://www.achewood.com/banner.php?banner=mwy_2.gif

jon's the one saying "hell of tubby"

the schef (adam schefter ha ha), Thursday, 8 March 2007 20:21 (eighteen years ago)

I am bald and fat. I will post shirtless pix of myself with Jon's face photoshopped onto my body to demonstrate what he's going to look like in ten years.

Rock Hardy, Thursday, 8 March 2007 20:23 (eighteen years ago)

"ten years"

jeff, Thursday, 8 March 2007 20:28 (eighteen years ago)

"ten years" :D

the schef (adam schefter ha ha), Thursday, 8 March 2007 20:28 (eighteen years ago)

2 weeks

JW, Thursday, 8 March 2007 20:29 (eighteen years ago)

hahahaha

Rock Hardy, Thursday, 8 March 2007 20:30 (eighteen years ago)


You must be logged in to post. Please either login here, or if you are not registered, you may register here.