lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20050312152353.I1945@ubzr.zsa.bet>
From: measl at mfn.org (J.A. Terranson)
Subject: Reuters: Microsoft to give holes info to
	UncleSam first - responsible vendor notification may not be a goodidea
	any more...


[Note: I have replied ONLY to the list.  Please correct the faulty headers
if you reply, so that people don't get 5 copies of things.  Thanks.]


On Sat, 12 Mar 2005, Jason Coombs wrote:

> The only fair disclosure policy is full disclosure.

I am not talking about a "fair" disclosure policy, I am referring to a
disclosure policy which serves a public policy interest (albeit at the
expense of the individuals within the aforementioned "public".

Critical infrastructure serves us ALL, and must be first on the fix wagon.
Whether it's a bunch of edge windows machines running EMS and PD or a
bunch of core routers making packets appear at your router, infrastructure
*should*, ALWAYS, come first.

> Regards,
>
> Jason Coombs
> jasonc@...ence.org

//Alif

-- 
Yours,

J.A. Terranson
sysadmin@....org
0xBD4A95BF

"Quadriplegics think before they write stupid pointless
shit...because they have to type everything with their noses."

	http://www.tshirthell.com/


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ