lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20050313032612.A14600@evita.devdas.geek>
From: devdas at dvb.homelinux.org (Devdas Bhagat)
Subject: Reuters: Microsoft to give holes info to Uncle
	Sam first - responsible vendor notification may not be a good
	idea any more...

On 12/03/05 15:36 -0600, J.A. Terranson wrote:
> 
> On Sat, 12 Mar 2005, Devdas Bhagat wrote:
> 
> > > Microsoft, Cisco, Juniper, etc., all have both vested interests and public
> > > policy interests in notifying those who would be most affected first.
> >
> > Which public? Are you a member of the public? Am I?
> 
> The public at large.  You , me, everyone you know is "the public".
> 
> 
> > > This is good public policy as well: if the national infrastructure is
> > > compromised, we are all up shit's creek, if Joe's Corner Store is
> >
> > Which nation? From my PoV, it is the general user who needs to be
> > informed first. A whole bunch of us have more problems with Windows
> > holes even though we do not use Windows, simply because of the traffic
> > volume generated.
> 
> Your "view" is perversely slanted towards serving only your own personal
> interests, without regard for those around you.
> 
> As such, your "view" is worthless, and can be safely discarded.
> 
My PoV is that the infrastructure that I depend on is being impacted by
J.R. User in the US, Korea and Japan because of the flood of crap that
comes from their infected Windows systems to mine. Hint: There is
network infrastructure outside the US.

Regardless of what you think critical infrastructure is, the US
government's PCs are /not/ critical infrastructure. 

Devdas Bhagat

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ