RE: [Full-Disclosure] Hotmail & Passport (.NET Accounts)

From: Ed Carp (erc_at_pobox.com)
Date: 05/12/03

  • Next message: Daniel Dočekal: "RE: [Full-Disclosure] MSN Webcam / Chat Spoof"
    To: "Mark J Cox" <mjc@redhat.com>, "Nick FitzGerald" <nick@virus-l.demon.co.uk>
    Date: Mon, 12 May 2003 09:54:06 -0500
    

    > > I sure hope that
    > > folk won't be sucked into bogus "MS released fewer IE patches last
    > > year" claims based solely on the year-on-year comparison of the
    > > number of patch releases (as indicated by security bulletin count).
    >
    > Most vendors and even open source software projects roll up security
    > fixes, usually when issues are classed as minor or if several severe
    > issues can be announced and fixed at the same time. To know how many
    > issues get rolled up you need to be able to count issues or
    > vulnerabilities and that can be quite subjective. However we can
    > normalise on CVE data to get useful statistics:

    Counting vulnerabilities is a ridiculous way of assessing security! Common
    sense should tell you that, an no explanation is needed for this very
    obvious fact.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Daniel Dočekal: "RE: [Full-Disclosure] MSN Webcam / Chat Spoof"

    Relevant Pages

    • Re: To Anyone who has Internet Explorer Installed or any other browser (Everybody)
      ... know the first thing about security. ... know about plans, fixes, manufacturer data, and -- perhaps most ... features) has less chance of dangerous flaws. ... why is it that Microsoft is STILL ...
      (alt.computer.security)
    • Re: checking for all known viruses vs. fixing the system
      ... ]>>> install a trojan horse on every computer so that they can automatically ... ]>>> change system software and configuration remotely any time they want to. ... and that said fixes may disable 3rd party software. ... ]> called it a security fix". ...
      (comp.security.misc)
    • RE: ARRRRGH! Guys, whos breaking -STABLEs GMIRROR code?!
      ... For security and "critical fixes" you can ... minds of the FreeBSD developers? ... manually merge fixes into your production source ...
      (freebsd-stable)
    • Re: latest firefox version for fc4
      ... Visiting mozilla.org I see that the current version of firefox is ... which fixes certain security issues. ... Don't like running things that may have security issues:( ... Well I mean for them to package it with the packages for FC4. ...
      (Fedora)
    • Supercookie
      ... While doing an online security scan, I was told I can a vulnerability because ... AuditMyPC.com's Quick Security Fixes ... Microsoft has added this SuperCookie to Internet ... Explorer 6 and it may also work in all previous versions of Internet Explorer ...
      (microsoft.public.security)