Advertisement
Promo

Security threats Toolkit

Story: Malware authors mixing a lethal cocktail

  • Previous comment

Posted by: non mouse (Thursday 9 December 2004, 7:10 PM)

  • Reply

Don't understand why she says she is against anyone who publishes vulnerabilities. Many times people find a hole, they approach M$/other software vendor and are ignored. The hackers know the vulnerabilities and share them amongst themselves. Sometimes, publishing the vulnerabilities is the only way to get the vendor to fix the problem.

By not publishing the vulnerabilities, the only people who get hurt are the admins who can't protect against something they don't know exists. The hackers will share the holes and exploit them regardless.

Maybe she means there should be a recommended delay between finding the hole, informing the vendor, and publishing?

  • Previous comment

  • Reply to this comment
  • Return to story
  • Report this as offensive


Full Talkback thread

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

2 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters