RE: [lists] Re: [Full-disclosure] F-Secure to release XSS "potential dangers"




Valdis.Kletnieks@xxxxxx wrote:
n3td3v said:

This is highly irresponsible of F-Secure and they should be held
legally responsible if the information they release in relation to
their "Netscape hacked" blog entry is used maliciously.

You might want to review what you've posted to lists
regarding vulnerabilities,
and ask yourself - if F-Secure gets held to some legal
standard of liability.
where do you end up yourself?

I don't know who's going to end up the test case/poster child
for vulnerability
liability - but it's much more likely to be an individual
that posts to
this list and can't afford a lawyer than a corporation with
deep pockets
like F-Secure....

:) n3td3v's mouth is going to get her in trouble one of these days.

Curt Purdy CISSP, GSNA, GSEC, CNE, MCSE+I, CCDA
Information Security Officer
Information Systems Security
infosysec.net
443.846.4231

-------------

If you spend more on coffee than on IT security, you will be hacked.
What's more, you deserve to be hacked.
-- former White House cybersecurity czar Richard Clarke

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • RE: F-Secure 2006 Review
    ... There sales and tech support are very knowledgeable. ... Information Security Coordinator ... Webroot or F-Secure as their spyware choice. ... firewall company to be paranoid, because people may be out to get me as ...
    (Security-Basics)
  • Re: [Full-disclosure] Securityfocus fall for n3td3v agenda to show up the security company
    ... F-Secure was originally in the wrong to report their recent "Your new ... You can bet they'll be an XSS worm on a social network doing something ... encourage security incidents and encourage "rent a quote" people to ... I know theres no XSS worm threat, ...
    (Full-Disclosure)
  • RE: F-Secure 2006 Review
    ... Webroot or F-Secure as their spyware choice. ... I've been running the trial of the security suite and I'm pretty pleased ... firewall company to be paranoid, because people may be out to get me as ... Support is available via e-mail and phone (if you can find the phone ...
    (Security-Basics)
  • Re: [Full-disclosure] F-Secure to release XSS "potential dangers"
    ... > F-Secure know the enemy of the Netscape web site are reading their blog: ... I see you notice that f-secure, a security company, have released ... If you read my post and the F-Secure blog properly, ...
    (Full-Disclosure)