, 2006-03-07
There is value in finding vulnerabilities. Yet many people believe that a vulnerability doesn't exist until it is disclosed to the public. We know that vulnerabilities need to be disclosed, but what role do vendors have to make these issues public?

infamous41md
a) not downplaying the significance of flaws
b) disclosing flaws to a public forum and making their users aware of them
c) working with researchers to fix the flaws since many vendor attempts at fixes seem rather inept
From ...
[ more ]