|
|
Subscribe / Log in / New account

vulnerability disclosure policies

vulnerability disclosure policies

Posted Dec 17, 2004 10:37 UTC (Fri) by DonDiego (guest, #24141)
Parent article: Students uncover dozens of Unix software flaws (News.com)

Whatever happened to informing authors/vendors of vulnerabilities first and giving them some time to patch the application before making issues public? I work on MPlayer and we were not informed prior to making the vulnerability public, a mail was sent to our users mailing list (not even the developers mailing list) at the same time it was sent out to the world. Irresponsible behavior IMNSHO.


to post comments

vulnerability disclosure policies

Posted Dec 17, 2004 12:24 UTC (Fri) by clugstj (subscriber, #4020) [Link]

Publicity Stunt.

vulnerability disclosure policies

Posted Dec 20, 2004 22:15 UTC (Mon) by darthmdh (guest, #8032) [Link]

Dan Bernstein doesn't believe in responsible disclosure. He believes programmers should be "punished" for bad code.

http://groups-beta.google.com/group/comp.security.unix/ms...

I agree, which is why I don't run qmail :-)


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds