MyBB Community Forums

Full Version: Responsible Vulnerability Disclosure
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3
The only thing I wish is to have a notify option/alert such as a mailing list otherwise have to visit often and see if there is an update.
(2018-09-12, 08:01 PM)vbgamer45 Wrote: [ -> ]The only thing I wish is to have a notify option/alert such as a mailing list otherwise have to visit often and see if there is an update.

You should be able to subscribe via mail to new Blog posts (Follow MyBB Blog via Email in the sidebar or Follow on the bottom right).
Thanks that makes it way easier
Many releases are on tragic days, so if you are concerned about it i think many other either and have no time to hack a forum.

Not all is abou United States, we are a communitty and many of us are out of there and that dates means nothing for users.

I think is the best way releasing security maintenance releases and the day is not important at all, at the end of the day all the people have to concern abput what is going around the entire world.

When their army attack others and kill millions like Siria or Africa, Israel, Irak, in all the entire world are tragic events but they work even that and that is really apreciated. So take your time and stay updated when you can.

Many of us are praying for the people and concerned so nobody are around hacking neither by ethic due all we are humans and we only take care of us as a communitty.


Think about all not only you mate, we all apreciate the hard work. The days when my country have experienced a high risk earthquakes all of us continue working and even now we do, dates are similars but life is a risk by itself.
(2018-09-12, 01:30 PM)Lunorian Wrote: [ -> ]Publishing the commit (https://github.com/mybb/mybb/commit/420b...089e9d4ca1) revealing a high risk security issue was irresponsible at the time it was disclosed. It should of waited until current disasters had calmed down a bit.

You're not serious right now.

You're basically saying that people elsewhere in the world are free to have continued vulnerability on their websites (a vulnerability that was no doubt disclosed to the team to be resolved, and therefore known about) - all while you wait for some heavy rain, flash flooding and winds.

I'm sorry, that's bloody selfish. As someone who feels that vulnerabilities in a platform need to be resolved at the earliest opportunity, I believe that this was done at the right time (as soon as it became known and was able to be resolved), so that people who are currently not experiencing inclement weather (read: The rest of the planet) could update successfully. You don't have to update immediately.

Fully with the team on this, they should fix vulnerabilities as soon as feasibly possible, bugger the day.
People are killing each other every day...while you're laying back and drinking a smoothie.
(2018-09-12, 01:30 PM)Lunorian Wrote: [ -> ]Hi everyone,

Yesterday MyBB released a security update in what's both a state of emergency on the east coast (several states at least!) of the USA (and likely elsewhere in the world - I only know about the hurricanes which are about to effect me but I hear there are more than one hurricanes out there right now), alongside a day of remembrance (9/11) where people are less likely to be working and checking for updates.

Currently the hurricanes threaten the lives of webmasters and our ability to respond to issues and install updates is somewhat limited at the moment.

Additionally you released an update on 9/11 which is a day of remembrance in the United States. Many people are with their families in memory of a tragedy and wouldn't of bothered to check for a MyBB Update.

Publishing the commit (https://github.com/mybb/mybb/commit/420b...089e9d4ca1) revealing a high risk security issue was irresponsible at the time it was disclosed. It should of waited until current disasters had calmed down a bit.

Can the development team please take a look at current events before publishing a security update and letting potential hackers "go wild" before we have time to safely install security patches during a time where both our lives are threatened and some of forced to remember a terrible event and wish to withdraw for the day?

Cordially,
Lunorian

My first thought was... 'Are you nucking futs?'

I'm 100% All-American, but not the rest of the world that uses MyBB as their choice of the forum software.

Here in the USA, we celebrate the 4th of July, but does that mean that Great Britain, Germany, Italy, India do not have their own 4th of July? 
Of course, they do! 

During the day of September 11th, what did I do? I recognize the tragedy and continued to pray for all victims of the terrorist act. 
I did other things, such as taking my dog in for her surgery (it was life-threatening, but she made it fine and she's back home recovering).

Bottom line, who cares WHEN something is released? Like many of these posts in here already... many dates throughout the year have some sort of significance to someone.

@MyBB Development team! DO NOT release anything on my birthday! What day is your birthday, Serpius? It's January 1st. (for real, if I could, I would show my ID proving this, but we don't trust the internet. Do we?)  Cool

Remember, the world doesn't revolve around you @Lunorian.
As said by others, we cannot release a security patch without it being inconvenient for some. We have to choose between releasing a patch quickly (after all, unless the vulnerability is discovered by a team member it has been reported to us - thus, it is known to AT LEAST one other person, potentially many who wish to exploit it) OR we can wait until the wind blows favourably putting hundreds of thousands of forums at risk.

While we appreciate that some in the US are experiencing adverse weather, we aren't going to slow down releases to accommodate this.
(2018-09-13, 12:10 PM)Serpius Wrote: [ -> ]
(2018-09-12, 01:30 PM)Lunorian Wrote: [ -> ]Hi everyone,

Yesterday MyBB released a security update in what's both a state of emergency on the east coast (several states at least!) of the USA (and likely elsewhere in the world - I only know about the hurricanes which are about to effect me but I hear there are more than one hurricanes out there right now), alongside a day of remembrance (9/11) where people are less likely to be working and checking for updates.

Currently the hurricanes threaten the lives of webmasters and our ability to respond to issues and install updates is somewhat limited at the moment.

Additionally you released an update on 9/11 which is a day of remembrance in the United States. Many people are with their families in memory of a tragedy and wouldn't of bothered to check for a MyBB Update.

Publishing the commit (https://github.com/mybb/mybb/commit/420b...089e9d4ca1) revealing a high risk security issue was irresponsible at the time it was disclosed. It should of waited until current disasters had calmed down a bit.

Can the development team please take a look at current events before publishing a security update and letting potential hackers "go wild" before we have time to safely install security patches during a time where both our lives are threatened and some of forced to remember a terrible event and wish to withdraw for the day?

Cordially,
Lunorian

My first thought was... 'Are you nucking futs?'

I'm 100% All-American, but not the rest of the world that uses MyBB as their choice of the forum software.

Here in the USA, we celebrate the 4th of July, but does that mean that Great Britain, Germany, Italy, India do not have their own 4th of July? 
Of course, they do! 

During the day of September 11th, what did I do? I recognize the tragedy and continued to pray for all victims of the terrorist act. 
I did other things, such as taking my dog in for her surgery (it was life-threatening, but she made it fine and she's back home recovering).

Bottom line, who cares WHEN something is released? Like many of these posts in here already... many dates throughout the year have some sort of significance to someone.

@MyBB Development team! DO NOT release anything on my birthday! What day is your birthday, Serpius? It's January 1st. (for real, if I could, I would show my ID proving this, but we don't trust the internet. Do we?)  Cool

Remember, the world doesn't revolve around you @Lunorian.

There's a difference between your birthday and a storm that might kill millions of people!
A huge quote for a single line?
There is a difference between real concern and a timepass thread attracting attention.
But you know what? That doesn't make your point any valid. Have a vote and you will see how far you have made yourself a joke trying to show the MyBB team infirior.
Pages: 1 2 3