Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'd like to hear a security expert's opinion on whether releasing even patched 0-days could be considered harmful ? even if the 'sploits dont work out of the box, it seems like they would still advance the state of the art, and allow moderately-skilled hackers to build on very sophisticated designs, adapt and make them effective again - "stand on the shoulders of giants" kind of thing.


Many things are patched in theory but not in practice. For example, exploits on Android are very useful even if they are patched because lots of people don't upgrade their smartphones very often.


Releasing the exploits is also the quickest way to get them patched.


In the Equation Group releases, there were 0-days for older versions of Cisco's ASA software.

Others built on that and updated it to also exploit newer versions (9.x, IIRC) of the software.


Thats a very interesting comment...

I am going to make a few assumptions: You have no kids. You're realatively young.

---

That said, lets unpack your comment... sure it would be good to explore this (as many people havent looked into the depth of the layers of cyber culture... few really and honestly understand it) - but the implications are fractally deep... if there are people who are diving into this, we shall never know. cyberwar is a known but also unknown thing... implecations are not known, but tactics appear to be revealing themselves.. how to attack... how to defend.

Firewalls are one-dimensional - we are talking 5+ dimensions with CW, arent we...

What are those 5Ds? think of OSI as 1 and add some layers... I would love your feedback....

(BTW, How many ppl work at [company] which are ex [service] - Why is it called 'The Company')




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: