RE: [Full-disclosure] Our Industry Is Seriously Ethics Impaired

From: security curmudgeon (jericho_at_attrition.org)
Date: 07/27/05

  • Next message: Williams, James K: "RE: [Full-disclosure] Our Industry Is Seriously Ethics Impaired"
    Date: Wed, 27 Jul 2005 17:30:22 -0400 (EDT)
    To: full-disclosure@lists.grok.org.uk
    
    

    On Wed, 27 Jul 2005, DAN MORRILL wrote:

    : So is 3com willing to lean on Oracle or Microsoft, or Real, or anyone
    : else to get the patch done in a reasonable time frame? So that the
    : finder of the issue does not get bored or angry or worried that someone
    : else will discover it and then claim full credit for it?

    Why would they lean on any vendor? It is in their best interest to let the
    vendor take as long as they want to fix an issue.

    Remember that they share this information with their paying clients, so
    the longer it is "0-day", the longer it is "exclusive" to 3com/clients,
    the more value it has. Pushing on a vendor to patch it faster doesn't do
    them near as much good in the end.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Williams, James K: "RE: [Full-disclosure] Our Industry Is Seriously Ethics Impaired"

    Relevant Pages