Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Mozilla's 'Code of Silence' Isn't
Jon Lasser, 2002-10-09

Developers are accused of not publicizing the browser's security vulnerabilities enough. But do we really need world wide alerts for every bug?

Comments Mode:
Cool a unix/lenix guy preaching the same stuff as M$crud 2002-10-09
Twinker (3 replies)
Cool a unix/lenix guy preaching the same stuff as M$crud 2002-10-09
Rob John <rdrj@mindspring.com> (2 replies)
My point was.... 2002-10-10
Twinker (1 replies)
Nothing's hidden 2002-10-15
Anonymous (1 replies)
Nothing's hidden 2002-10-15
Karl
Mozilla's 'Code of Silence' Isn't 2002-10-09
Chad Loder
Mozilla's 'Code of Silence' Isn't 2002-10-10
Jon Lasser (2 replies)
Mozilla's 'Code of Silence' Isn't 2002-10-16
Serge Wroclawski
Mozilla's 'Code of Silence' Isn't 2002-10-10
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-10
Twinker (2 replies)
Mozilla's 'Code of Silence' Isn't 2002-10-11
XandreX (1 replies)
Mozilla's 'Code of Silence' Isn't 2002-10-11
Anonymous (2 replies)
Mozilla's 'Code of Silence' Isn't 2002-10-14
Anonymous
..And THAT is exactly what MS is advocating. For the past one year, Scott Pulp and his ilks have been saying "It's not so much that we hate disclosure. We are just concerned about the methodologies of such disclosure. It would be great if you let us control those methodologies"

MS even co-opted some "Security" research companies into forming a a sort of alliance with them such that they become privy to 0-day fixes from MS in exchange for NOT disclosing bugs. IIRC, SecurityFocus was one of the "very few" Security houses that that refused to join this alliance. Now, with your article, regardless of how you couch it, what you are advocating is in direct conflict with the SecurityFocus' position in the course of this "Responsible Disclosure" brouhaha. I sincerely hope it's NOT an indication of things to come from SF, now that you have been owned (or gone Corporate).

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/114/16793#16793
Mozilla's 'Code of Silence' Isn't 2002-10-15
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-12
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-12
Anonymous
Practice what you preach 2002-10-13
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-13
Anonymous
Mozilla's 'Code of Silence' Isn't 2002-10-16
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus