How to be Transparent About Security Issues
It was bound to happen to Habari eventually, right? And in the dark recesses of my mind, I’m happy for two reasons. First because at last we merit inspection by “security consultants”. Second because we are staffed well enough to have addressed the issue within a reasonable amount of time. But some questions have arisen about how to handle security announcements, and there are distinct sides on the issues.
People are going to publish security notices about your software whether you want them to or not. Sometimes there is altruism at work - people want others to know that something is unsafe. Sometimes it’s open malice - people sharing secrets of how to exploit software for their own malicious uses. In either case, as a software author, you can’t control what people say about you, and specifically what exploits in your software they expose to the world. So in the end, security exploits result in more spin control than controlling the information.