Security threats Toolkit
Story: Massive IE phishing exploit discovered
Why not inform Microsoft about an exploit first?
Errr, because doing it Microsoft's way doesn't lead to the desired results perhaps? Because complying with Microsoft's PR damage control policies leaves a bad taste in the mouth? Because knowing that there's a big problem within a certain product that still isn't fixed 200+ days later while the vendor of that product is still putting massive amounts of money in lying to the world how secure they are is not something all professionals can carry with them day in, day out?
Full Talkback thread









