Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't understand why you would call Steve Gibson out on this.[1] What is the connection between Yubico and Steve Gibson?

[1]: For the sake of the discussion I will pretend he is a qualified to speak about security.



The closest connection I can find is that Steve endorses the Yubikey. I guess if you consider Steve Gibson to be a reliable source on security, you would expect his endorsement to carry some weight and likewise, the withdrawal of his endorsement to matter. So if you can pressure Steve into withdrawing his support, you would be in a winning situation.

That's assuming you consider Steve Gibson to know anything at all about security.


Cheap shot. Gibson may not be current, but he's one of the few out there trying to explain issues to a wider audience who are outside of our bubble, and he does a fairly good job at it (though I wish he'd give Leo LaPorte a good slap).


He's also made a fool out of himself in very unashamed and public ways, and spread a lot of FUD. Windows XP raw sockets and Windows meta file come to mind. He's also said that Metasploit is a controversial piece of software that's main use is to develop malware.

Steve Gibson is a talker, even if he doesn't know what he's talking about. He will say whatever he wants and issue corrections later when he's been proven wrong. It's not a cheap shot. It's well documented, he's been called out on it for years, but he's still calling himself a security expert while simeltaneuously spewing bullshit, for 15 years now.

And "not current" in security means "useless", or sometimes "actively harmful". There is no way to call yourself a security expert if you're out of date.

http://attrition.org/errata/charlatan/steve_gibson/


Gibson Research introduced a lot of people to security. I doubt anyone believes he's the foremost expert at any one thing in particular. He's earned a lot of respect for making security easy for new folks.


Are we talking about the same Gibson that had some scare mongering web page, then capitalized on that by selling magic make-my-computer-faster software? That's some blast from the past.


The one that said raw sockets in Windows XP was going to break the internet




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: