Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Disclosure Survey
Federico Biancuzzi, 2006-09-05

Federico Biancuzzi surveys statements from some of the world's largest software companies about vulnerability disclosure, interviews two security companies who pay for vulnerabilities, and then talks with three prominent, independent researchers about their thoughts on choosing a responsible disclosure process. In three parts.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Re: Disclosure Survey 2006-09-05
Matthew Murphy
You are very right, timeliness is the biggest sticking point without question. What's a reasonable timeframe? There's no good answer that can be generally applied. It changes from issue to issue.

Most vendors prefer to err on the side of limited disclosure -- that is, they prefer to wait until...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus