|
|||||||||||
|
Re: Internet Explorer 0day exploit
From: Chris Stromblad <cs(at)outpost24.com>
Date: Wed Jul 18 2007 - 16:17:13 EDT
Hello,
Bigby Findrake wrote:
>> One more thing about "advisories". I think it would be better to release >> them immediately and let people know what they are facing. With public >> dissemination of a vulnerability perhaps someone will release a 3rd >> party patch or another inventive way of protecting oneself. Holding it >> "secret" really doesn't help anyone. > > With regards to your last statement, I would like to believe that that's > so, or at least that if there is some harm in "early release" of > information that that harm is mitigated (if not outright outweighed) by > the potential good that's done by alerting the community and thereby > allowing them to develop their own responses. Exactly. Why is it that many people seem to agree that it's less likely that something bad will happen if information is not disclosed. I'd say it's an equal, if not bigger, chance that something good happens. It's all about proportions really. There is likely more "good" people out there than "bad". If x % of the good guys look at it, they will likely count for a higher number of people as compared to an equal % x of the bad. So, yes... I believe that immediate information disclosure about a bug is better. It shortens the exposure window and it certainly does put more pressure on the vendor to come up with a patch. > Yeah, let's stay away from speculation and assumptions for now. > >> Anyways, enough ranting. > > I, for one, enjoyed your rant. Well thank you, perhaps I should do it more often. > / Chris
90 Long Acre
iD8DBQFGnnVJ+CG0a/ZJxn8RAmTsAKDRcGi+6jyPpWQofxyaWaOjg2w33gCfSWTj
MHqg5Up5AvwBIvcWc0Lbj70=
This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:09:49 EDT |
||||||||||
|
|||||||||||