Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Charney an Ominous Microsoft Pick
Tim Mullen, 2002-02-11

What are we to make of Microsoft tapping a former hacker prosecutor and IP lawyer for its top security spot? Nothing good.

Comments Mode:
Charney an Ominous Microsoft Pick 2002-02-11
The Real World (3 replies)
Charney an Ominous Microsoft Pick 2002-02-12
trowe
"This philosophy works great in labs and universities. However, in the real world, where businesses base their
existance on information, full disclosure (i.e. disclosure without allowing the vendor to publish a patch first) is
wreckless and irresponsible. (To all the flamers: I don't work for MS, and I don't excuse security vulnerablities.) "

I don't think most of the responsible people interested in security are proponents of publishing an exploit before the vendor has a chance to release a fix. However, if the vendor has been notified, yet not responded, or released a fix in 30days...60 days...then it's resonable to publish the vulnerability in order to perhaps light a fire under them. Personally I would be willing to live with knowing the exploit is there, and how to prevent it, if possible while the vendor works on a fix. *After* the fix is released, or the vendor fails to respond in a reasonable time, then publish the mechanics of it. This is NOT what MS wants. They want us to *never* know the mechanics unless we have a contract with one of their "approved" partners. That is nuts.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/59/10481#10481
Charney an Ominous Microsoft Pick 2002-02-15
Serious_Poo
Charney an Ominous Microsoft Pick 2002-02-19
Road Rules
DRM OS and vulnerability disclosure 2002-02-11
batz (1 replies)
Charney an Ominous Microsoft Pick 2002-02-12
Richard H. Rowson (1 replies)
Charney an Ominous Microsoft Pick 2002-02-12
Anonymous
Charney the Lawyer 2002-02-12
David (1 replies)
Charney the Lawyer 2002-02-25
Name withheld by request
Charney an Ominous Microsoft Pick 2002-02-12
Esqape (1 replies)
Charney an Ominous Microsoft Pick 2002-02-15
Anonymous
Charney an Ominous Microsoft Pick 2002-02-25
Anonymous (1 replies)
Charney an Ominous Microsoft Pick 2002-02-27
Anonymous
Charney an Ominous Microsoft Pick 2002-02-27
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus