Stories
Slash Boxes
Comments

SoylentNews is people

Log In

Log In

Create Account  |  Retrieve Password


MichaelDavidCrawford (2339)

The Fine Print: The following are owned by whoever posted them. We are not responsible for them in any way.
Tuesday December 04, 18
03:13 AM
Security

Don't worry - I won't.

I won't tell a human soul other than those in a position to fix it, however it's a systemic weakness, and cannot be fixed by issuing patches. This problem won't get fixed until the IETF issues some future RFCs - more than one of them - and even then, not until those new standards are _widely_ implemented.

I've never mentioned this in a public way - this is the very _first_ time I've done so - and I've only told one other person that I know how, but not how it would be done.

If you're in a position to implement new RFCs at your company, or in your contributions to a Free Software or Open Source codebase that you are a _commiter_ to, please fetch my OpenPGP key from a keyserver, if your key isn't already there, please submit it then _email_ your key fingerprint - I think that's 16 digits of hex or so - then I'll add it to my keyring.

$ gpg --keyserver pgp.mit.edu --list-keys 69297A03F84E2022
pub rsa4096 2018-11-18 [SC] [expires: 2023-11-17]
            87741D160E80D4F860A192FE69297A03F84E2022
uid [ultimate] Michael David Crawford
sub rsa4096 2018-11-18 [E] [expires: 2023-11-17]

Note that I do not yet have a key for mike@soggywizards.com.

$ gpg --keyserver pgp.mit.edu --receive-key 69297A03F84E2022

Please do _not_ sign my key - nor anyone else's - unless I show your my _passport_ in your direct presence. That my technical articles are so popular led a few complete strangers who I'd never met to sign my old key. The key I've got now is _only_ self-signed.

Please keep it that way until we meet for coffee. But not a beer; I only get drunk when a close friend has been unlucky in love. Then we both Pray To The Porcelain God.

I must be purposefully oblique about the details I provide until I can feel certain not just that those who I share this with will keep a lid on it but also until I've found enough RFC-implementors that once I do provide the details, they'll be able to apply the fixes expeditiously.

It happens that I know some primary developers of some stacks. I also know some leading security experts. I'll explain this to a few of them first. I'm on good terms with some vendors' security people, I'll explain it to them as well.

Display Options Threshold/Breakthrough Reply to Article Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: -1, Troll) by Anonymous Coward on Tuesday December 04 2018, @04:36AM (2 children)

    by Anonymous Coward on Tuesday December 04 2018, @04:36AM (#769438)

    I welcome the destruction of the internet because it will mean egotistical narcissistic assholes like you will lose your precious fucking soapbox which you use to shit on the rest of us. Without your global communication network, your influence extends only as far as you can shout. The next time you open your mouth to attract attention, enjoy getting punched in your fucking thoat, motherfucker.

    Shut it down now, you lying piece of shit. Do it. Do it now.

    SHUT DOWN THE INTERNET RIGHT NOW.

    Fuck you, Crawford. Fuck you to Hell. Fuck you Forever.

    FUCK MDC

  • (Score: -1, Troll) by Anonymous Coward on Tuesday December 04 2018, @04:41AM

    by Anonymous Coward on Tuesday December 04 2018, @04:41AM (#769439)

    Or death to Michael David Crawford, I don't care which.

    Preemptive "go fuck yourselves, you cunts" to all the MDC supporters.

    Fuck MDC

  • (Score: -1, Troll) by Anonymous Coward on Tuesday December 04 2018, @04:55AM (1 child)

    by Anonymous Coward on Tuesday December 04 2018, @04:55AM (#769441)

    Our interwebs, we needs them!

    Terrorist! Terrorist! Terrorist!

    Send SWAT teams to shoot Michael David Crawford in the head.

    Fuck MDC

    • (Score: 0) by Anonymous Coward on Tuesday December 04 2018, @08:18PM

      by Anonymous Coward on Tuesday December 04 2018, @08:18PM (#769733)

      Stop Threatening our National Securities

      Our? I thought national security was only for people who had jobs? I guess I'll have to do some more research on that point.

  • (Score: -1, Troll) by Anonymous Coward on Tuesday December 04 2018, @04:59AM

    by Anonymous Coward on Tuesday December 04 2018, @04:59AM (#769442)

    Take it down now, Dickhead.

    I eagerly await headline news about you as soon as paper newspapers become a thing again when the internet is gone forever.

    DO IT NOW. TAKE DOWN THE INTERNET.

    Fuck you, Crawford.

    Do it. Now.

    Also, fuck you.

    FUCK MDC

  • (Score: -1, Troll) by Anonymous Coward on Tuesday December 04 2018, @05:04AM (3 children)

    by Anonymous Coward on Tuesday December 04 2018, @05:04AM (#769443)

    ...then flush your head down the toilet.

    Have a shit day and fucking die real soon, shithead.

    Oh and I want the internet GONE and you gone with it.

    Fuck MDC

    • (Score: 2) by MichaelDavidCrawford on Tuesday December 04 2018, @07:46AM (2 children)

      by MichaelDavidCrawford (2339) Subscriber Badge <mdcrawford@gmail.com> on Tuesday December 04 2018, @07:46AM (#769459) Homepage Journal

      That's time you would have better put to use by wandering the desert wearing a hairshirt and beating yourself with chains.

      --
      Yes I Have No Bananas. [gofundme.com]
      • (Score: -1, Troll) by Anonymous Coward on Tuesday December 04 2018, @01:54PM

        by Anonymous Coward on Tuesday December 04 2018, @01:54PM (#769537)

        Drop dead.

        Fuck MDC

      • (Score: 0) by Anonymous Coward on Wednesday December 05 2018, @10:44AM

        by Anonymous Coward on Wednesday December 05 2018, @10:44AM (#770016)

        You just devoted five posts to me?

        Such is the way of Salty Spice.

        Salty seems really angry, so I guess he's been applying for jobs, or he shorted oil last week and took a bath in the market when oil popped 5% over the weekend.

        tl;dr - It's not easy being Salty.

  • (Score: 2) by MichaelDavidCrawford on Tuesday December 04 2018, @07:48AM

    by MichaelDavidCrawford (2339) Subscriber Badge <mdcrawford@gmail.com> on Tuesday December 04 2018, @07:48AM (#769460) Homepage Journal

    ... and you're going to like it or I'm gonna sidomize you sideways with a supersonic telephone pole."

    In other news, while I'm able to mostly speak intelligibly I can easily tell that I'm unable to move my lips and tongue correctly.

    This leads to my plan to request my new Neurologist refer me to a speech therapist.

    --
    Yes I Have No Bananas. [gofundme.com]
  • (Score: -1, Spam) by Anonymous Coward on Tuesday December 04 2018, @12:02PM (3 children)

    by Anonymous Coward on Tuesday December 04 2018, @12:02PM (#769502)

    Why does the internet still exist, you lying turd?

    Why have you not destroyed the internet yet, you lying turd?

    "Famed Security Researcher Michael David Crawford Demonstrates Design Flaw By Breaking Entire Internet"

    Why are you not headline news yet, you lying turd?

    "Greatest Genius Of Our Time Michael David Crawford Receives Michael David Crawford Award In His Own Honor"

    Why have you not received the attention and prestige you so richly deserve, you lying turd?

    Why are you a lying turd, Crawford?

    Fuck MDC

    • (Score: 2) by MichaelDavidCrawford on Tuesday December 04 2018, @12:27PM (2 children)

      by MichaelDavidCrawford (2339) Subscriber Badge <mdcrawford@gmail.com> on Tuesday December 04 2018, @12:27PM (#769506) Homepage Journal

      I'm quite certain there are some others who know about the underlying problems, but having spent some time watching the news - mostly here at Soylent, also Tech News like Ars Technica - has convinced me that I'm the only one who knows how to create this particular exploit.

      I'm not even remotely seeking credit, rather, I want the problem _fixed_.

      --
      Yes I Have No Bananas. [gofundme.com]
      • (Score: -1, Spam) by Anonymous Coward on Tuesday December 04 2018, @01:51PM (1 child)

        by Anonymous Coward on Tuesday December 04 2018, @01:51PM (#769536)

        I'm the only one who knows how to create this particular exploit.

        Prove it. Shut down the internet.

        Fuck MDC

        • (Score: 0) by Anonymous Coward on Wednesday December 05 2018, @10:46AM

          by Anonymous Coward on Wednesday December 05 2018, @10:46AM (#770017)

          Prove it. Shut down the internet.

          But if MDC does shut down the intertubes you won't be able to post here to tell him that he was right and you were wrong. See the dichotomy?

  • (Score: 5, Interesting) by realDonaldTrump on Tuesday December 04 2018, @12:11PM (1 child)

    by realDonaldTrump (6614) on Tuesday December 04 2018, @12:11PM (#769503) Homepage Journal

    But, come to my Winter White House. We'll have cake -- the most beautiful cake you've seen in your entire life. And let's talk about closing up that internet. Because we're loosing a lot of people. And Bill Gates is too busy to see me!!!

  • (Score: 0) by Anonymous Coward on Tuesday December 04 2018, @05:46PM (1 child)

    by Anonymous Coward on Tuesday December 04 2018, @05:46PM (#769676)

    Hey Michael,

    I think you need to take a step back and look at things from an outside perspective:
    1. You have a friend who has a history of delusional episodes.
    2. Your friend has had a recent health issue that was very severe.
    3. Less than a week after suffering from some neurological symptoms (possibly related to #2), this friend has become convinced that they have, single-handedly, identified a severe security weakness in a key piece of infrastructure that has gone unnoticed by everyone else who has interacted with it.
    4. This friend has also made similar (in magnitude) claims in the past that did not turn out to be realistic or actionable.

    What should you say to this friend?
    Should you tell them to be patient, recover fully from their health problems, and then look at the problem at least a week later? If the problem has been around for a long time, then surely it could be present for a little while longer (importance: high, but urgency: low).

  • (Score: 2) by The Mighty Buzzard on Tuesday December 04 2018, @06:31PM (1 child)

    by The Mighty Buzzard (18) Subscriber Badge <themightybuzzard@proton.me> on Tuesday December 04 2018, @06:31PM (#769688) Homepage Journal

    I'm not particularly concerned if someone breaks it. I've a fair stockpile of porn locally and can always use a good excuse to go fishing.

    --
    My rights don't end where your fear begins.
    • (Score: 0) by Anonymous Coward on Wednesday December 05 2018, @10:49AM

      by Anonymous Coward on Wednesday December 05 2018, @10:49AM (#770018)

      And there you have it, ladies and gentlemen. Porn is the reason more people don't go fishing.

  • (Score: 2) by MichaelDavidCrawford on Wednesday December 05 2018, @07:44AM

    by MichaelDavidCrawford (2339) Subscriber Badge <mdcrawford@gmail.com> on Wednesday December 05 2018, @07:44AM (#770001) Homepage Journal

    "Find My iPhone" FTW.

    Fortunately I could still get online _through_ the phone with its Personal Spot.

    The geolocation wan't precise enough so I used "Play Sound".

    --
    Yes I Have No Bananas. [gofundme.com]
  • (Score: -1, Spam) by Anonymous Coward on Wednesday December 05 2018, @12:48PM

    by Anonymous Coward on Wednesday December 05 2018, @12:48PM (#770046)

    Why does the internet still exist, Dickhead?

    Shut down the fucking internet, you lying shit.

    You are a colossal disappointment, Crawford.

    Fuck MDC

  • (Score: -1, Spam) by Anonymous Coward on Wednesday December 05 2018, @12:55PM

    by Anonymous Coward on Wednesday December 05 2018, @12:55PM (#770048)

    Do like the sweet young things half your age you sleep with, and be disruptive.

    Disrupt the internet right now. You know you can do it.

    Fuck MDC

  • (Score: -1, Spam) by Anonymous Coward on Wednesday December 05 2018, @01:00PM

    by Anonymous Coward on Wednesday December 05 2018, @01:00PM (#770049)

    Fix our internets! Save us from the Ruskies!! Save us from the Norks!!!

    Defeat those cyber dragons in those cyber windmills with your magic lance!!!!

    Make the internet a safe space for safe spaces, Don Slippery Dickhead!!!!!!!!!!!

    Fuck MDC

(1)