Re: [Full-Disclosure] Information Week: 2/3 of pros want immediate disclosure

From: Jason Coombs (jasonc_at_science.org)
Date: 07/09/04

  • Next message: Jason Coombs: "[Full-Disclosure] [Fwd: A FINFlash from the Freedom to Innovate Network]"
    To: "Ingevaldson, Dan (ISS Atlanta)" <dsi@iss.net>
    Date: Thu, 08 Jul 2004 21:30:27 -1000
    
    

    Ingevaldson, Dan (ISS Atlanta) wrote:
    > What would the results look like if you asked a loaded question that
    > leaned in the other direction?
    >
    > "Should software vendors disclose information about software
    > vulnerabilities to the global hacking community at the same time as all
    > their customers who haven't yet implemented a working patch management
    > process?"

    How about this one, too, so we'll know the technical competency of the
    people who provide answers to the first two questions:

    "Do you believe it is possible for software vendors to disclose
    information about software vulnerabilities to their customers without
    the global hacking community learning about that disclosure?"

    Any answer other than "No." would prove the respondant is not qualified
    to give answers to such questions.

    Sincerely,

    Jason Coombs
    jasonc@science.org

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Jason Coombs: "[Full-Disclosure] [Fwd: A FINFlash from the Freedom to Innovate Network]"

    Relevant Pages

    • Re: Lisp IDE for GNU/Linux
      ... Not that it matters -- FOSS simply is and always will be. ... Customers were also free to exchange patches with other licensed ... non-disclosure rules in the source licenses. ... One of the best ways non-free software vendors could improve their ...
      (comp.lang.lisp)
    • Re: IBM obsoleting mainframe hardware
      ... If they said to customers, we won't support you any more because you aren't current, software vendors would lose a lot of business. ... For IBM-MAIN subscribe / signoff / archive access instructions, ... send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO ...
      (bit.listserv.ibm-main)