lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
From: guninski at guninski.com (Georgi Guninski) Subject: Hotmail & Passport (.NET Accounts) Nick FitzGerald wrote: > > Whether you like it or not, MS has a policy governing acknowledgement > of vulnerability discoverers/reporters: > > http://www.microsoft.com/technet/security/bulletin/policy.asp > Back in around 1997/1999 ms credited (almost) anyone who bothered to disclose a bug - check their bulletins. After then this changed. My explanation is that they realized there are *a lot* of bugs left and tried to pressure people who bothered to disclose bugs to them to keep hush until they fix the bugs. My 2 stotinki, Georgi