, SecurityFocus 2005-12-15
The auction may have set a record price for a highlighter pen and an 8-by-11-inch sheet of paper.
Expand all |
Post comment
Researchers: Flaw auctions would improve security
2005-12-18
Anonymous (2 replies)
Anonymous (2 replies)

And who else wants that flaw and why? What true significance does this flaw hold for anyone but the developer of the software to fix? I stand by eBay's decision to pull the "pen and paper". I also feel that software companies should have a reward system. Paying for flaws once the extent/criticality of the flaw is determined. Their policy should be public as well as pricing. The better the pay, the more people will hunt for that hidden egg, the more secure the product? In theory yes. Flip side of that is that companies that can dish out the money might skimp on the security and code testing in the beginning but that just means more money to the independent testers. Still sounds good to me.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/11364/32883#32883