Hello,

martin f krafft wrote:
If you don't give us a name, we can't credit you. We will not say
that "mysterious [EMAIL PROTECTED] found that..."

there was a discussion on pen-test about anonymity, so I won't start that here again. But maybe some of the arguments mentioned there are necessary to change your mind. I cannot see what the hell you need a "name" for.


Sorry, anonymity only has a certain degree of utility.

Some arguments from the discussion (not a quote): rfp, mudge, Gwendolynn ferch Elydyr - are that names you would accept? How do you decide that a name or mail adress is fake - would a post from "Fook Yoo" be allowed? If it was [EMAIL PROTECTED], [EMAIL PROTECTED]

So, IMHO at least you could tell the people that [EMAIL PROTECTED] found that vulnerability - it's *the author's* choice to give his real name, a name - do you think you can proof that? - or simply nothing. You _do have_ the email adress.

GTi

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

Reply via email to