webOS Nation Forums >  webOS apps and software >  webOS discussion > CNBC: Security Experts 'Shocked' by Palm's WebOS Vulnerabilities
CNBC: Security Experts 'Shocked' by Palm's WebOS Vulnerabilities

  Reply
 
LinkBack Thread Tools Display Modes
Old 04/16/2010, 05:30 PM   #21 (permalink)
News Contributor
 
akitayo's Avatar
 
Join Date: Apr 2009
Posts: 1,586
Likes Received: 53
Thanks: 114
Thanked 637 Times in 240 Posts
Default

If all the bugs of 1.3.5 were fixed with 1.4 IMO it was not smart to post this info and just when Palm is about to launch Pre Plus and Pixi plus with 3 carriers, O2, Vodafone and SFR.

Who wants to make evil damage to Palm at this time, with old news, already not happening anymore.

I suggest to make an addedum on front page, something like NO MORE BUGS ON WEBOS AFTER 1.4.1 more or less.
akitayo is offline   Reply With Quote
Old 04/16/2010, 09:04 PM   #22 (permalink)
Member
 
Join Date: Jan 2010
Posts: 39
Likes Received: 0
Thanks: 2
Thanked 5 Times in 5 Posts
Default

Quote:
Originally Posted by akitayo View Post
If all the bugs of 1.3.5 were fixed with 1.4 IMO it was not smart to post this info and just when Palm is about to launch Pre Plus and Pixi plus with 3 carriers, O2, Vodafone and SFR.

Who wants to make evil damage to Palm at this time, with old news, already not happening anymore.

I suggest to make an addedum on front page, something like NO MORE BUGS ON WEBOS AFTER 1.4.1 more or less.
Ya this is like posting on facebook saying your neighbors wife is a **** and not telling him directly. Either your trying to screw up their relationship or you really went about adressing the concern the wrong way.
usnis0922 is offline   Reply With Quote
Old 04/16/2010, 11:38 PM   #23 (permalink)
Member
 
Join Date: Nov 2003
Location: Philly, PA
Posts: 2,766
Likes Received: 5
Thanks: 38
Thanked 183 Times in 154 Posts
Default

So two lies make a right?
Quote:
Originally Posted by akitayo View Post
I suggest to make an addedum on front page, something like NO MORE BUGS ON WEBOS AFTER 1.4.1 more or less.
__________________
Pixi: Sold. Pre: Passed off to another rep. Touchpad: Just a toy until Cloud syncing arrives, and a better doc editor.
crogs571 is offline   Reply With Quote
Old 04/17/2010, 01:05 AM   #24 (permalink)
Member
 
Join Date: Sep 2009
Posts: 404
Likes Received: 0
Thanks: 10
Thanked 131 Times in 56 Posts
Default

Quote:
Originally Posted by 6tr6tr View Post
Was the SMS vulnerability patched? Can anyone point me to real evidence of this?
The video that the security group released specifically mentions that 1.4 is not vulnerable, and that Palm fixed the issue after it was reported to them.

The way that responsible disclosure works is you report the vulnerability to the company first, allow them to develop a patch, wait until after the patch has been released, and then report on the vulnerability in public. That is the path that was followed here.
Tiddlekins is offline   Reply With Quote
Old 04/17/2010, 01:11 AM   #25 (permalink)
Member
 
Join Date: Aug 2005
Posts: 832
Likes Received: 0
Thanks: 29
Thanked 99 Times in 65 Posts
Default

Quote:
Originally Posted by Tiddlekins View Post
The video that the security group released specifically mentions that 1.4 is not vulnerable, and that Palm fixed the issue after it was reported to them.

The way that responsible disclosure works is you report the vulnerability to the company first, allow them to develop a patch, wait until after the patch has been released, and then report on the vulnerability in public. That is the path that was followed here.

The issue i have is.. it's VERY misleading. And almost hides the fact that they have patched these issues, with words like shocked and not safe.

This same exact article can be re-written.. Palm Quick to fix issues brought to them. But this is a New OS and platform.. things will be found.

But a good pen tester can prob tear into WebOS pretty good.
antonio3 is offline   Reply With Quote
Reply

 

Thread Tools
Display Modes



 


Content Relevant URLs by vBSEO 3.6.0