While it may be considered poor practice a lot of vendors act as if it is a rule that all must go by. That is of course a fallacy. Vendors should be tripping over themselves to thank researchers who bother to do so. Where else would you get top-drawer talent to test your apps, and at no cost I might add. These very same multi-billion dollar corporations are the ones who let market forces dictate s/w development timelines, and then whine when they get spanked. They need to take far more proactive action in writing better code, and yet more care in dealing with security researchers instead of bludgeoning them with corporate lawyers which some have done.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/newsbriefs/58/220#220