, 2002-10-09
Developers are accused of not publicizing the browser's security vulnerabilities enough. But do we really need world wide alerts for every bug?
Expand all |
Post comment
Cool a unix/lenix guy preaching the same stuff as M$crud
2002-10-09
Twinker (3 replies)
Twinker (3 replies)
Cool a unix/lenix guy preaching the same stuff as M$crud
2002-10-09
Rob John <rdrj@mindspring.com> (2 replies)
Rob John <rdrj@mindspring.com> (2 replies)
Mozilla's 'Code of Silence' Isn't
2002-10-10
Twinker (2 replies)
Twinker (2 replies)
Mozilla's 'Code of Silence' Isn't
2002-10-11
XandreX (1 replies)
XandreX (1 replies)

MS even co-opted some "Security" research companies into forming a a sort of alliance with them such that they become privy to 0-day fixes from MS in exchange for NOT disclosing bugs. IIRC, SecurityFocus was one of the "very few" Security houses that that refused to join this alliance. Now, with your article, regardless of how you couch it, what you are advocating is in direct conflict with the SecurityFocus' position in the course of this "Responsible Disclosure" brouhaha. I sincerely hope it's NOT an indication of things to come from SF, now that you have been owned (or gone Corporate).
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/114/16793#16793