RE: 0-day exploit..do i hear $1000?

From: Steve (steve@securesolutions.org)
Date: 10/18/01


From: "Steve" <steve@securesolutions.org>
To: "'RT'" <roelof@sensepost.com>, "'rain forest puppy'" <rfp@wiretrip.net>
Subject: RE: 0-day exploit..do i hear $1000?
Date: Thu, 18 Oct 2001 14:24:55 -0600
Message-ID: <003101c15812$f4406100$f554b8a1@workstation1>


> I stand corrected. Read in an e-zine that you are a "security
> consultant". Assumed it was your own company.

I had a teacher back in high school who used to say "Never assume, you
make an ASS out of U and ME". Still, I don't see your point, so what if
RFP had his own consulting company? Are you saying that if he has his
own vacuum cleaner company we would see all kinds of zero day vacuum
exploits? That's a pile of crap, *most* of the researchers I have come
into contact with in my career do their research primarily because it is
interesting to them *not* to simply start up a consulting firm and make
some money.

Yes, some of us are forced to do things like pay bills and support
families, consulting is one of those ways but consulting should not be
the reason behind the research. If it was, most would be like a certain
start up that releases vague white papers and only gives full details to
their paying customers.
 
> So do we. We just also want to make a living doing it. We
> don't rape the industry - we contribute where we can.

There is nothing wrong with making a living. But there is something
wrong with doing research just to promote your business. In my opinion
anyways.

 
> RFP, the way I see this business is like this. You do your
> job, try to do it better that the dude next door, build
> cutting edge technology, release it to the public (as its
> stupid to think that no-one else will get it anyhow) and use
> it to get your company name out there, while you contributing
> to the industry as a whole. Does that mean selling out? I hope not.

It doesn't mean selling out, but its organizations who care more about
the press they will get vs. the good they can do who cause Microsoft to
write articles like the "Information Anarchy". Your research should not
be to simply get your company name out there, it should be to better arm
the IT community and help them protect themselves.

There is nothing wrong with making sure your company name is on an
advisory, but there is something very wrong in doing the research just
to prove how smart your employees are.
 



Relevant Pages

  • Re: Need Your Opinions
    ... your choice to spend 13 years with IBM before you began consulting. ... But in the consulting business, ... since when does a consultant dictate the time span of a project? ... the only language anyone should program in. ...
    (comp.lang.php)
  • Re: OT: A different perspective on Outsourcing
    ... >Merely Following a Megatrend ... >compete with companies like I.B.M. for more lucrative consulting work. ... >pose to American competitors. ... >in terms of relationships and business value. ...
    (rec.boats)
  • Re: Need Your Opinions
    ... I've been consulting since 1990. ... And certainly not something like you're talking, which is critical to their business. ... thinking that a $10 ph consultant will cost you more in the long run than a $20 ph consultant is not accurate math...and a complete failure on the hiring party to protect the company's interests. ... your 'rules' statement is akin to saying language A is the only language anyone should program in. ...
    (comp.lang.php)
  • Open positions in Denver CO, Southern California & Tempe AZ
    ... information technology consulting and software solutions. ... achieve strategic business goals. ... BT INS is seeking a top notch SharePoint ...
    (microsoft.public.sharepoint.portalserver)
  • Re: what is best way to learn sbs2003
    ... I think that especially from the perspective of a consulting practice, ... the most popular events around small business consulting (if not the most ... And his books are great as well. ... You can become an MS registered partner at no cost, ...
    (microsoft.public.windows.server.sbs)