, 2003-10-27
Whether it's a student slipping contraband past airport metal detectors, or a researcher modeling an unstoppable computer virus -- demonstrations just don't do justice to the real state of security.
Expand all |
Post comment

Should researchers be punished or not? You left out how you go about proving a flaw exists without attempting to do it? Also, companies don't react unless there is "real" proof that is reproducible. Afterall, companies (government included) don't want to spend time or money running around everytime "Chicken Little" screams "The sky is falling!"
Most networks are more secure this month compared to last month because the virii have actually abused the various exposed flaws. If people don't have to apply patches, they haven't been.
I know from personal experience I had been ignored by my own company until the flaws exposed how serious the Microsoft bugs were. Or how serious some of the Cisco bugs were ... etc.
Your own posting is more flawed in it's argument than the article.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/194/23429#23429