Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Flaws,exploits and zero-days should they be kept secret?
Search Topic:
Uniqs:
167
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Emailing Anonymously, with Outlook or another client »
« Malwarebytes VS Iobit question.  
AuthorAll Replies

sharpy merc

join:2003-01-28
England

Flaws,exploits and zero-days should they be kept secret?

This is an incredibly two sided argument.

The YES camp: with the less people who know the easier it is to fix (and pretend it was never there). Point of view

The NO camp: With the more its published the faster it'll get fixed (sadly many more people will be affected, till it is). attitude

so whats your take and what camp are you in?

BTW if an argument makes you change your mind in either direction that would be interesting


TearAbite

join:2001-07-25
Rancho Cucamonga, CA
i guess NO:
If i find an exploit, that means that all the people that are smarter than me will also find it at some point.. I would notify the manufacturer, give them some time to react (say, 30 days) - THEN publish it (without exact details)..


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub
reply to sharpy merc
The question is much to simple, it depend on. Varied factor and circumstances play a role so I can not vote with yes or no. Every flaw/exploit have to be analysed/judged on itself.


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T U-Verse
·AT&T Midwest

reply to sharpy merc
The best practice, as far as I can tell is:

Immediately notify the developers of the affected software. Ideally, the developers will start working on a solution.

Notify the general public when any of the following have occurred:
(a) the developer has an effective solution that is ready to be put in place;
(b) information on the flaw has already leaked, so the public needs to be warned;
(c) substantial time has passed, the developer does not seem to be working on the problem, and publication is the only way to put pressure on the developer.

It is my impression that such practices are already followed by many.
--
AT&T Uverse; Zyxel NBG334W router (behind the 2wire gateway); openSuSE 11.0; firefox 3.0.15
-
Forums » Up and Running » Security » SecurityEmailing Anonymously, with Outlook or another client »
« Malwarebytes VS Iobit question.  


Sunday, 29-Nov 07:40:44 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [73] Weekend Open Thread
· [72] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· AV-Comp. Retrospective/Proactive Test 11/2009 released [Security]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· Are GPS's better today? [General Questions]
· Road Runnner up to 50 mbps is ready ! [Road Runner]
· Using DIR-615 C1/3.01 with Trendnet TEW-652BRP in N Mode [D-Link]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· [Newsgroups] Newzleech down? [Filesharing Software]