/begin rant lemme think, a recall a post on a list somewhere, that involves a person that found security hole in hp-ux or something, hp was notified many times in apparently a 90 day period, without even bothering to reply to the messages, at which point the guy posted to bugtraq or elsewhere, which resulted in HP making a claim that they reserve the right to hold the person that released the information responisble for any exploitation that might incur as a result. I think after i got threatened in that way a few times, i might use anonymous email addresses as well. it all comes down to what exactly is the correct general practice for full disclosure and to what degree vendors should be held responsible. especially in a case like this, my opinion is that if vendor is notified and ignore such notification, in this manner, vendor should without doubt be held responsible, even considering that whitehat releases an exploit at some point, if that exploit is used against me, and i know that vendor was notified over 90 days ago, yet decided not to take action or even notify me that there may be a security hole in a product i purchased from them, I think it is reasonable to assume the vendor was negligent and knowingly allowed a product with a secutiry hole to breech my network. I think i should be able to hold the vendor responsible, but with the way things look, vendors have deeper pockets than the whitehats which will likely result in vendors never being notified about security holes and those exploits will stay underground. vendors should make clear what their policies are on full disclosure, and make it even more clear how they handle those that find such holes or bugs, whether or not they will try to make them responsible or if they will reward them for using proper notification procedures, that may help a whitehat, or even blackhat, for that matter, to decide exactly what method they should use with that vendor when it comes to disclosing what may have been found. /end rant
sorry, just some things that come to mind. i'll go have my cofee with lots of sugar now. Don > >-----Original Message----- > >From: [EMAIL PROTECTED] > >[mailto:[EMAIL PROTECTED]]On Behalf Of Dave Salovesh > >Sent: Wednesday, July 31, 2002 8:07 AM > >To: '[EMAIL PROTECTED]' > >Subject: RE: Web Messaging Hack (was: RE: [IMail Forum] ) > > > > > >> person reporting. If the person thought it was so important to post on > >> bugtraq, why use such an address? > > > >If he didn't, we'd all know what Sandy does in his spare time. > > > >Oops. > > > >-- > >Dave Salovesh > >RAM Associates, Inc. > >(800 or 202) 543-3635 > > > > > >Please visit http://www.ipswitch.com/support/mailing-lists.html > >to be removed from this list. > > > >An Archive of this list is available at: > >http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > > > >Please visit the Knowledge Base for answers to frequently asked > >questions: http://www.ipswitch.com/support/IMail/ > > Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
