, 2005-06-21
Expand all |
Post comment
Interview with Marcus Ranum
2005-06-22
some guy in Central PA (1 replies)
some guy in Central PA (1 replies)
Interview with Marcus Ranum
2005-06-22
Anonymous (1 replies)
Anonymous (1 replies)
Re: Interview with Marcus Ranum
2005-06-22
Marcus Ranum (2 replies)
Marcus Ranum (2 replies)
Interview with Marcus Ranum
2005-06-22
Tails (2 replies)
Tails (2 replies)
Re: Interview with Marcus Ranum
2005-06-22
Marcus Ranum (7 replies)
Marcus Ranum (7 replies)
What A Total Jackass
2005-06-22
Anonymous (1 replies)
Anonymous (1 replies)
Interview with Marcus Ranum
2005-06-24
Anonymous (2 replies)
Anonymous (2 replies)

>But that wouldn't be fun, would it? The hackers >want the power of ultimate self-determination, >and none of the responsibility. Unfortunately, >things don't work that way for very long.
I don't know about fun, but MSFT pays or used to pay @tstake, Foundstone, Core, Ernst and Young, and many other computer security consulting companies to review IIS among other things.
I'm not sure if its to better their security or buy their silence. I'm sure they all had to sign NDA's. Why publish an IIS hole when MSFT will pay $100's of thousands of dollars for you to find it and silently fix it?
Is that better for the community at large? What about the software companies that can't pay for the fansy "hackers"? Maybe they have security vulnerabilities that only the NSA and the hackers employed by the Chinese government know.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/334/32078#32078