, SecurityFocus 2001-11-09
Five computer security firms join Microsoft to set an official standard for limiting disclosure of software security holes
Expand all |
Post comment
Shocking developments
2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (2 replies)
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (2 replies)
Such a policy for disclosure already exists
2001-11-09
Dumky (1 replies)
Dumky (1 replies)
Such a policy for disclosure already exists
2001-11-10
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]>
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]>
...on second thought...Kudos!
2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (1 replies)
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (1 replies)
So what would force Microsoft to patch these holes if exploits are not published?
2001-11-10
Rafal Sybilla-Leszczynski (1 replies)
Rafal Sybilla-Leszczynski (1 replies)
So what would force Microsoft to patch these holes if exploits are not published?
2001-11-12
Anonymous
Anonymous
Microsoft have no server monopoly: this may reduce their share
2001-11-12
Kirsten Bayes (kirruth@hushmail)
Kirsten Bayes (kirruth@hushmail)

Consider,
- company/person X finds a flaw and advises M$ of it
- the rest of us get the promised limited disclosure
- I hear about the bug, but details are too sketchy for me to identify systems at risk.
- I get hacked
- fix is released & full disclosure occurs
- I can now see that with the extra info I could have identified my systems at risk.
Am I not now in a position to sue? My business has sufferred a loss. It was a loss which people knew about and deliberately withheld the info I could have used to mitigate the damage. Am I not able to make a case that their withholding that information harmed me.
In the past (and the present) the quick answer was M$ has deeper pockets and can run you round court till you die. But now, I have five fresh and presumably smaller targets I can hit who are all sharing the same info we are told.
Are these guys not road kill that just hasn't seen the headlights yet?
Enno.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/281/8758#8758