vulnerability disclosure policies
vulnerability disclosure policies
Posted Dec 17, 2004 10:37 UTC (Fri) by DonDiego (guest, #24141)Parent article: Students uncover dozens of Unix software flaws (News.com)
Whatever happened to informing authors/vendors of vulnerabilities first and giving them some time to patch the application before making issues public? I work on MPlayer and we were not informed prior to making the vulnerability public, a mail was sent to our users mailing list (not even the developers mailing list) at the same time it was sent out to the world. Irresponsible behavior IMNSHO.
Posted Dec 17, 2004 12:24 UTC (Fri)
by clugstj (subscriber, #4020)
[Link]
Posted Dec 20, 2004 22:15 UTC (Mon)
by darthmdh (guest, #8032)
[Link]
http://groups-beta.google.com/group/comp.security.unix/ms...
I agree, which is why I don't run qmail :-)
Publicity Stunt.vulnerability disclosure policies
Dan Bernstein doesn't believe in responsible disclosure. He believes programmers should be "punished" for bad code.vulnerability disclosure policies