Re: Public disclosure of discovered vulnerabilities

Date: 05/17/05

Date: Tue, 17 May 2005 07:10:42 -0500

"Douglas A. Gwyn" <> wrote in message
> If you're talking about specific products, it makes
> sense to contact the developers and give them time to
> fix the problem before spreading the word. In the case
> of widespread (endemic) problems where it is not
> feasible to reach all the (potential) developers, there
> isn't much choice other than to publish the problem.

I think most folks consider that the reasonable approach, and it's the
one that many if not most white hats try to take.

Unfortunately, certain vendors absolutely refuse to fix a security hole,
often denying that it exists even when presented with irrefutable
evidence, unless it's made public and customer pressure becomes
significant. There's nothing to be gained by delaying public release of
the information when dealing with such vendors, since it just means
it'll be longer until a patch comes out and thus the bad guys have more
time to attack ignorant users.

In contrast, one vendor I worked with would fix security bugs and ship
patches (without telling customers what they fixed) as quickly as
possible but request that the person discovering it withhold public
release until (a) an exploit was seen in the wild or (b) six months
elapsed. The latter almost always held and so by the time they
announced the vulnerability, nearly all of their customers were already
running patched software. This is about the best response I can


