When you agree to the software licenses and agreements you can't hold them responsible for anything, so good luck....
Neil ----- Original Message ----- From: "Don Weber" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, July 31, 2002 1:27 PM Subject: OT: Web Messaging Hack (was: RE: [IMail Forum] ) > > /begin rant > lemme think, a recall a post on a list somewhere, that involves a person > that found security hole in hp-ux or something, hp was notified many times > in apparently a 90 day period, without even bothering to reply to the > messages, at which point the guy posted to bugtraq or elsewhere, which > resulted in HP making a claim that they reserve the right to hold the person > that released the information responisble for any exploitation that might > incur as a result. I think after i got threatened in that way a few times, i > might use anonymous email addresses as well. it all comes down to what > exactly is the correct general practice for full disclosure and to what > degree vendors should be held responsible. especially in a case like this, > my opinion is that if vendor is notified and ignore such notification, in > this manner, vendor should without doubt be held responsible, even > considering that whitehat releases an exploit at some point, if that exploit > is used against me, and i know that vendor was notified over 90 days ago, > yet decided not to take action or even notify me that there may be a > security hole in a product i purchased from them, I think it is reasonable > to assume the vendor was negligent and knowingly allowed a product with a > secutiry hole to breech my network. I think i should be able to hold the > vendor responsible, but with the way things look, vendors have deeper > pockets than the whitehats which will likely result in vendors never being > notified about security holes and those exploits will stay underground. > vendors should make clear what their policies are on full disclosure, and > make it even more clear how they handle those that find such holes or bugs, > whether or not they will try to make them responsible or if they will reward > them for using proper notification procedures, that may help a whitehat, or > even blackhat, for that matter, to decide exactly what method they should > use with that vendor when it comes to disclosing what may have been found. > /end rant > > sorry, just some things that come to mind. > i'll go have my cofee with lots of sugar now. > > Don > > > >-----Original Message----- > > >From: [EMAIL PROTECTED] > > >[mailto:[EMAIL PROTECTED]]On Behalf Of Dave Salovesh > > >Sent: Wednesday, July 31, 2002 8:07 AM > > >To: '[EMAIL PROTECTED]' > > >Subject: RE: Web Messaging Hack (was: RE: [IMail Forum] ) > > > > > > > > >> person reporting. If the person thought it was so important to post on > > >> bugtraq, why use such an address? > > > > > >If he didn't, we'd all know what Sandy does in his spare time. > > > > > >Oops. > > > > > >-- > > >Dave Salovesh > > >RAM Associates, Inc. > > >(800 or 202) 543-3635 > > > > > > > > >Please visit http://www.ipswitch.com/support/mailing-lists.html > > >to be removed from this list. > > > > > >An Archive of this list is available at: > > >http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > > > > > >Please visit the Knowledge Base for answers to frequently asked > > >questions: http://www.ipswitch.com/support/IMail/ > > > > > > Please visit http://www.ipswitch.com/support/mailing-lists.html > to be removed from this list. > > An Archive of this list is available at: > http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > > Please visit the Knowledge Base for answers to frequently asked > questions: http://www.ipswitch.com/support/IMail/ > Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
