Hi -
On Mar 12, 2008, at 3:30 AM, Gert Doering wrote:
Personally, I think there is no way besides "do not code security holes" to make everybody happy - and I'm fine with the proposed schema. Provided the mechanism "knowledge appears in the wild -> immediate release" works.
FWIW, we actually had an event exactly like this happen on Thursday. The 'Cisco Secure Access Control Server for Windows User-Changeable Password Vulnerabilities' Advisory we published then was not scheduled to go out until April 9th. Due to some information about the vulnerability being published, we went ahead and started our Advisory publishing process.
In this case it took less than 4 hours for us to publish our Advisory (and the accompanying AMB document) from the time we were aware of the disclosure.
The same process applies to IOS advisories as well, as it always has. Regards, Clay
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [EMAIL PROTECTED]
fax: +49-89-35655025 [EMAIL PROTECTED]
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
PGP.sig
Description: This is a digitally signed message part
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
