Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Exploit Code on Trial
Kevin Poulsen, SecurityFocus 2003-11-23

Security pros gathering at a Stanford University Law School conference on responsible vulnerability disclosure Saturday harmonized on the principle that vendors should be privately notified of holes in their products, and given at least some time to produce a patch before any public disclosure is made. But there was pronounced disagreement on the question of whether or not researchers should publicly release proof-of-concept code to demonstrate a vulnerability.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Screw the vendors? Screw the users at the same time. 2003-12-02
Alun Jones
Where to start, where to start...

Your post is short-sighted. First, there quite obviously are several people working for product vendors who care very deeply about the security of their products.

Second, publishing an exploit, particularly as you say, "easy to use code", is going to result i...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus