Firefox buffer overflow and full disclosure
Posted Sep 17, 2005 15:35 UTC (Sat) by
RobSeace (subscriber, #4435)
In reply to:
Firefox buffer overflow and full disclosure by giraffedata
Parent article:
Firefox buffer overflow and full disclosure
> Are these ever defects where some consumers would be hurt just by the
> publication?
Once again, I don't buy that the "publication" would be responsible for
anyone getting "hurt"... The flaw already exists; merely remaining silent
about it doesn't change the fact... In fact, as I've stated, remaining
only 'partially' silent (ie: informing the vendor, and thereby indirectly
who-knows-how-many people, whose morals and ethics you know nothing about)
is definitely worse... Remaining COMPLETELY silent (as in telling NO ONE
at all, and not using the info yourself) is safe enough, for now... Until
someone else comes along and discovers the same flaw... (If one person can
find it, so can another... In fact, in all likelihood, the chances are good
that someone else has previously already discovered the flaw, and simply
haven't told anyone yet...) So, the only rational course that I can see is
to inform the public at large, so they can protect themselves...
(
Log in to post comments)