[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <200208020515.BAA21064@linus.mitre.org>
From: coley at linus.mitre.org (Steven M. Christey)
Subject: it's all about timing
On Wed, 31 Jul 2002, Eric N. Valor wrote:
>>RFPolicy always seemed reasonable to me.
Joey Kelly asked:
>Got a URL for that?
http://www.wiretrip.net/rfp/policy.html
RFPolicy is an excellent document, which much of the responsible
disclosure draft is based on. However, it focuses on the researcher.
The responsible disclosure draft also includes recommendations for
vendors that would make it easier on researchers who want to follow
RFPolicy. Where RFPolicy says "give the vendors X working days to
respond," the RVDP has recommendations for researchers to give vendors
X days, and complementary guidelines for vendors to respond within X
days. (X = 5 for RFPolicy and X=7 for RVDP, as discussed in a
previous email).
- Steve
Powered by blists - more mailing lists