Re: [fw-wiz] recent disclosure debates

From: Marcus J. Ranum (mjr@ranum.com)
Date: 12/17/02


To: "R. DuFresne" <dufresne@sysinfo.com>, "'firewall-wizards@honor.icsalabs.com'" <firewall-wizards@honor.icsalabs.com>
From: "Marcus J. Ranum" <mjr@ranum.com>
Date: Tue Dec 17 08:17:00 2002

R. DuFresne wrote:
>I'm wondering why all the fingers are pointing so dramatically at ISS and
>why ISC has received little or no heat in the issue.

Probably because ISC wasn't marketing itself based on the
fact that its code was buggy, but ISS was marketing itself
based on the fact that it had found bugs in ISC's code.

As long as customers sit back and keep lapping up the whole
vulnerability-disclosure-as-marketing phenomenon, we'll keep
having to put up with it. I used to think that it'd wear
off but that was 5 years ago, already. I'd expected a
backlash of customer nausea long before now. I guess P.T. Barnum
was wrong: there's one born every _SECOND_.

mjr.

---
Marcus J. Ranum				http://www.ranum.com
Computer and Communications Security	mjr@ranum.com


Relevant Pages

  • Re: [fw-wiz] recent disclosure debates
    ... | By ISS' admission at the time, no 3rd party exploit code seemed to exist. ... the vendors who re-distribute ISC code didn't get enough time. ... when they told the vendor about the problem, ... being too close-mouthed about vulnerability information. ...
    (Firewall-Wizards)
  • Re: [fw-wiz] recent disclosure debates
    ... [Once again, this is my personal opinion, and not the position of ... By ISS' admission at the time, no 3rd party exploit code seemed to exist. ... If it's worth it for ISS to not just let ISC give them credit, ... > their free software to get people to buy into a consortia. ...
    (Firewall-Wizards)
  • Re: [fw-wiz] recent disclosure debates
    ... > I'm wondering why all the fingers are pointing so dramatically at ISS and ... > why ISC has received little or no heat in the issue. ... > followed there was a coordinated effort that failed when it came time to ... > make the patches available to the public, after members of BIND Forum were ...
    (Firewall-Wizards)
  • Re: [fw-wiz] recent disclosure debates
    ... bind 8 info update regarding ISS ... vulnerabilities in popular services. ... ISC BIND organization. ...
    (Firewall-Wizards)
  • bind 8 info update regarding ISS
    ... vulnerabilities in popular services. ... that have audited the source code of Bind, SSH, etc ... and overlooked the discrepencies that ISS picks up on. ... ISC BIND organization. ...
    (Bugtraq)