MyBB Community Forums

Full Version: Responsible Vulnerability Disclosure
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3
I just had a look back through your posts. You reported a vulnerability to us last year in September during hurricane Maria. At the same time it was passing over the Caribbean and 27 people died. Should you not have reported that in case one of the dev team members was in the Caribbean at the time?

We can’t always release patches at the most opportune time, and delaying them for the sake of a storm, no matter how bad it is, in a single country could have security consequences for the remaining 95% of the world’s population. In fact, if you look at how many people are currently being evacuated, 1.7 million, that represents only 0.02% of the world’s population.

While we sincerely hope no boards are compromised which are operated by those living in the path of hurricane Florence, we cannot delay a release for the tiny percentage of people this may affect. If we did, and set that as a precedent, we would likely never release an update.

Should we hold back for landslides in India? Droughts in Africa? Wildfires in California? Cyclones in Asia? Bushfires in Australia? At any given time 1/4 to 1/3 of the world’s population is asleep - what time of day do we release? On any given day you might expect 1/365 of the world’s population to have heir birthday (assuming no biases) which represents 0.27% of the world’s population. There are more than 1 billion Muslims and more than 1 billion Christians, each have religious observances. Do we not release updates during Ramadan? What about at Easter?
(2018-09-14, 07:02 AM)Tom K. Wrote: [ -> ]Bushfires in Australia?

If you waited until there was no bushfire in Australia, nothing would ever get done.
(2018-09-13, 03:10 PM)Lunorian Wrote: [ -> ]
(2018-09-13, 12:10 PM)Serpius Wrote: [ -> ]@MyBB Development team! DO NOT release anything on my birthday! What day is your birthday, Serpius? It's January 1st. (for real, if I could, I would show my ID proving this, but we don't trust the internet. Do we?)  Cool

Remember, the world doesn't revolve around you @Lunorian.

There's a difference between your birthday and a storm that might kill millions of people!

That statement I made was done with a heavy dose of SARCASM! 

[Image: giphy.gif]
Unfortunately Lunorian there is never good time to issue an update. The team issue the update and it is your choice on when you make the update to your forum.

Look at it this way.

#1 The issue or bug has been found.
#2 It goes through the report process.
#3 Then it goes to Github.
#4 They discuss it.
#5 Maybe they fix it.
#6 They release a test.
#7 Then they release the update when it's ready.

That issue/bug has been there on our forums for (Who knows how long) it's not a big deal to wait a couple of days or even weeks before the end user performs the update.

I always wait 3 or 4 weeks before updating and let others that know more than me sort out the problems (there usually are some), but I have recently decided to stop updating 18 just like I did with 16, it works for me on the .release I am on now and that is my choice.

Indeed sad times at the moment for the USA, but we all have sad times from all corners of the world or in our private lives.

Don't worry about the update, you can do it tomorrow / next week / next month / or just stay where you are, I doubt anything will happen to your forum and if you have a good host with backups then you can always just go back a day and start a fresh.

Spend your time worrying about the problems in your country or your family & friends first, your forum is safe.

Smile
MyBB's staff are hard workers and obviously care about their consumers. They don't owe us anything, yet they are freely giving away this beautiful software, allowing people to freely look into all that code and improve on it. That I chose MyBB over other FOSS such as phpBB and SMF in the last ten-plus years goes to show that they are on the right track. Unfortunately, life happens, and you have to understand that these are real people with real things going on outside of whatever you see below the URL bar on your browser.

So, for me, it doesn't matter when a new release is issued. Just that it IS issued is the point. Instead of complaining, let's be grateful that they are more active again. You wouldn't be any better with keeping up with maintaining popular software for nearly or over twenty years, so let the developers take their time to figure things out. If that's not up to fancy, then you're more than welcome to use a different software. I really don't see why that's difficult to comprehend.
Pages: 1 2 3