/begin rant
lemme think, a recall a post on a list somewhere, that involves a person
that found security hole in hp-ux or something, hp was notified many times
in apparently a 90 day period, without even bothering to reply to the
messages, at which point the guy posted to bugtraq or elsewhere, which
resulted in HP making a claim that they reserve the right to hold the person
that released the information responisble for any exploitation that might
incur as a result. I think after i got threatened in that way a few times, i
might use anonymous email addresses as well. it all comes down to what
exactly is the correct general practice for full disclosure and to what
degree vendors should be held responsible. especially in a case like this,
my opinion is that if vendor is notified and ignore such notification, in
this manner, vendor should without doubt be held responsible, even
considering that whitehat releases an exploit at some point, if that exploit
is used against me, and i know that vendor was notified over 90 days ago,
yet decided not to take action or even notify me that there may be a
security hole in a product i purchased from them, I think it is reasonable
to assume the vendor was negligent and knowingly allowed a product with a
secutiry hole to breech my network. I think i should be able to hold the
vendor responsible, but with the way things look, vendors have deeper
pockets than the whitehats which will likely result in vendors never being
notified about security holes and those exploits will stay underground.
vendors should make clear what their policies are on full disclosure, and
make it even more clear how they handle those that find such holes or bugs,
whether or not they will try to make them responsible or if they will reward
them for using proper notification procedures, that may help a whitehat, or
even blackhat, for that matter, to decide exactly what method they should
use with that vendor when it comes to disclosing what may have been found.
/end rant

sorry, just some things that come to mind.
i'll go have my cofee with lots of sugar now.

Don

> >-----Original Message-----
> >From: [EMAIL PROTECTED]
> >[mailto:[EMAIL PROTECTED]]On Behalf Of Dave Salovesh
> >Sent: Wednesday, July 31, 2002 8:07 AM
> >To: '[EMAIL PROTECTED]'
> >Subject: RE: Web Messaging Hack (was: RE: [IMail Forum] )
> >
> >
> >> person reporting. If the person thought it was so important to post on
> >> bugtraq, why use such an address?
> >
> >If he didn't, we'd all know what Sandy does in his spare time.
> >
> >Oops.
> >
> >--
> >Dave Salovesh
> >RAM Associates, Inc.
> >(800 or 202) 543-3635
> >
> >
> >Please visit http://www.ipswitch.com/support/mailing-lists.html
> >to be removed from this list.
> >
> >An Archive of this list is available at:
> >http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
> >
> >Please visit the Knowledge Base for answers to frequently asked
> >questions:  http://www.ipswitch.com/support/IMail/
> >


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to