|
BugTraq
Vulnerabilities in some SCADA server softwares Mar 21 2011 04:16PM Luigi Auriemma (aluigi autistici org) (1 replies) Re: Vulnerabilities in some SCADA server softwares Mar 21 2011 05:11PM J. Oquendo (sil infiltrated net) (4 replies) Re: Vulnerabilities in some SCADA server softwares Mar 23 2011 08:28PM Pavel Kankovsky (peak argo troja mff cuni cz) Re: Vulnerabilities in some SCADA server softwares Mar 23 2011 03:27PM Kent Borg (kentborg borg org) (1 replies) Re: Vulnerabilities in some SCADA server softwares Mar 23 2011 08:10PM J. Oquendo (sil infiltrated net) Re: Vulnerabilities in some SCADA server softwares Mar 22 2011 09:24PM Michal Zalewski (lcamtuf coredump cx) (2 replies) RE: Vulnerabilities in some SCADA server softwares Mar 23 2011 02:43PM Jim Harrison (Jim isatools org) (1 replies) Re: Vulnerabilities in some SCADA server softwares Mar 23 2011 04:54PM Luigi Auriemma (aluigi autistici org) Re: Vulnerabilities in some SCADA server softwares Mar 21 2011 08:02PM Luigi Auriemma (aluigi autistici org) |
|
Privacy Statement |
Sent from my mobile launching platform...
On Mar 22, 2011, at 16:24, Michal Zalewski <lcamtuf (at) coredump (dot) cx [email concealed]> wrote:
>> Analogy: Car owner has his car speed up ending up in almost near
>> catastrophe. Car owner goes to media outlets condemning the
>> manufacturer: "How could you be so reckless! Thousand of lives..."
>> Reality: Car manufacturer was never made aware of the issue. How do you
>> propose a manufacturer fix an issue?
>
> Yes, the discussion definitely needed a car analogy...
>
> The author decided to follow a particular route, probably not out of
> malice, but because he believes that his responsibilities to inform
> the public outweigh the responsibility to assist the vendor. You
> wouldn't do the same, but you haven't discovered these bugs.
>
> Unless your view is that you would rather not know about about
> security problems at all, than see a disclosure mode you do not agree
> with, I do not think it's fair to lash out against the reporter; and
> it's not particularly fitting to do so on BUGTRAQ.
>
> /mz
[ reply ]