lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
This website is powered by Openwall GNU/*/Linux security-enhanced OS
[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
From: gud at gmx.co.uk (Gordon McKillop)
Subject: A Few Realities About Security Re: Microsoft Cries Wolf ( again )

You said it, dude.

It sounds like secresearcher was talking out his ass.

If theres a vuln discovered in a piece of software everyone should know 
straight away. That way the attackers and defenders are on an even playing 
ground; patch up, disable or run the risk.

If you leave people in the dark then who knows who else knows about the vuln?

All the vulnerable systems sit unpatched and undisabled.

If one guy found it, another one could too, and he might not be as altruistic 
as the first guy.

Take it easy,
Gud.

On Friday 04 Jul 2003 2:14 am, Justin Shin wrote:
> Note the name:
>
> [full-disclosure]
>
> -- Justin Shin
> ----- Original Message -----
> From: <infosysec@...hmail.com>
> To: <secresearcher@...hmail.com>; <full-disclosure@...ts.netsys.com>
> Sent: Thursday, July 03, 2003 6:41 PM
> Subject: RE: A Few Realities About Security Re: [Full-Disclosure] Microsoft
> Cries Wolf ( again )
>
>
>
> OK secresearcher, I call you on this one.  If you're not completely full
> of crap, release the vuln the day before M$ does.  If you do, I will
> personally bow to you and publically eat crow.  If you don't, please
> go away.
>
> Curt
>

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux