Categories: Uncategorized

A Little Help Here, Please

Well, that was a close one: this blogger pointed out to Hossein “Hoder” Derakhshan that there was a security flaw in one of Tucows’ newly-acquired products, Blogrolling.com. Hoder pointed out the flaw and even suggested that people start mucking around with the Blogs for Bush blogroll. Dan Gillmor, Silicon Valley’s best-known journalist, picked up on Hoder’s blog entry and posted a quick blurb about the flaw.

Hoder essentially said “Crackers and electronic maladroits of the
world, here’s a flaw in a piece of software used by thousands of
bloggers, and here’s how you exploit it. Get to work”, and Dan, who’s
got to be one of the most-read guys on the Web, made sure lots of
people found out. But neither of these guys — both of whom are
otherwise generally decent folk — contacted Tucows.

We are lucky that there are a lot of people
with goodwill towards this company (in fact, this goodwill is one of
the reasons I accepted a job here). Brent Ashley and a number of people contacted us,
and we had a fix up in less than an hour.


It irks me that I have to say this, because I thought it would be obvious. Let me put it in large type:

The right thing to do when you discover a security flaw in a product is to contact the vendor.

The wrong thing to do is simply to assume that vendors deserve to get
0wnz0red simply because there’s a flaw in their product. Although we
strive for perfection, no piece of software is perfect; it’s just not
possible this side of paradise. We don’t put security flaws in our
software to “punk” our customers. In this world, you’re always refining
your work to adapt to ever-changing conditions, hence security guru
Bruce Schneier’s famous motto: “Security is a process, not a product.”

We’re all for full disclosure and free speech, but please tell us when our fly is down so we have a chance to pull it back up!

If you ever find a security flaw in any Tucows product, please let us
know. Hey, as the Technical Community Development Coordinator, you can
tell me (my email address is jdevilla@tucows.com),
and I’ll make sure that the appropriate actions are taken and even pull
as many strings as I can to make sure we send an appropriate token of
our gratitude. That’s my job.

As for Hoder and Dan, all I will say is “Shame on you.”


Related reading: Boss Ross’ take.

Sort-of related reading:

A lovely lass checks me out at a bar, and my buddy tells everybody at the table…except me.
AddThis Website Tools
Joey deVilla

View Comments

Recent Posts

A reminder for April Fools’ Day

Have a good April Fools’ Day tomorrow, but be mindful about your pranking.

3 weeks ago

How NOT to sell a computer

As I’ve written before, I sometimes browse Facebook Marketplace for nothing more than pure entertainment,…

3 weeks ago

Happy 10th anniversary, Anitra!

Ten years ago today, this happened: And since that day, it’s been an adventure. Thank…

2 months ago

Happy Valentine’s Day 2025!

Have a great Valentine’s Day, everybody.

2 months ago

Last Sunday’s accordion gig in Bonita Springs

It’s been over a year since I’ve played with Tom Hood’s band, the Tropical Sons.…

3 months ago

My plans for Burns Night 2025

Here’s the main course for dinner tonight... ...and that’s because it’s January 25th today, making…

3 months ago