Re: Windows Oday release



On 2007-06-13 13:03-0400, Steven M. Christey wrote:

The time line is also interesting, BTW:

Disclosure timelines are some of the most entertaining and educational
reading in security advisories. There's now (finally) enough data for
somebody somewhere to do a quantitative study on reported timelines,
including typical vendor response times, and issues in the process. (If
someone wants to pursue this, feel free to contact me to bat ideas
around.)

A lot of researcher timelines show a delay between the original discovery
and vendor notification. In some cases, this can be due to additional
time required to prove that the discovery is exploitable in order to give
a more reliable report to the vendor, but that's not always the case.

Thomas Lim though knows what he is doing and willing to stand behind
what he reports. Nowadays the vendors I am worried about are the open
source ones.

This is not about lost maintainers or non-existent patches, that's been
done to death. Reporting vulnerabilities to distributions can be so
depressing - and the replies you get (if any) are so annoying, that if
it was from Microsoft, they would have been grilled in the press already
for them.


- Steve

Gadi.



Relevant Pages

  • Re: Value from unbound form control
    ... I understand what you're saying about the extra field for a preferred phone ... since each vendor may have several. ... the person generating the report. ... button's Click event that opens the report). ...
    (microsoft.public.access.reports)
  • Re: Value from unbound form control
    ... I understand what you're saying about the extra field for a preferred phone ... since each vendor may have several. ... the person generating the report. ... button's Click event that opens the report). ...
    (microsoft.public.access.reports)
  • Re: Value from unbound form control
    ... PhoneNumber since each vendor may have several. ... DoCmd.OpenReport "rptVendorInfo", acPreview,, strLinkCriteria ... of the person generating the report. ... intended (in the command button's Click event that opens the report). ...
    (microsoft.public.access.reports)
  • Regarding excellent web hosting by Defined.net
    ... we are happy to report that we only have ... Defined is located in Southern California where we originally did business ... Defined was acquired by new a new owner, Chuck, a while back, and we now ... anyone who is not getting a response from a vendor to examine the ...
    (borland.public.delphi.thirdpartytools.general)
  • Re: Nearest Common Ancestor Report (XDb1s $1000 Challenge)
    ... >> It should not matter HOW my implementation generates the report. ... >is more likely to experience problems over a broader scope. ... Clear out 'john' and press enter. ... with no need to contact the vendor. ...
    (comp.object)