When you agree to the software licenses and agreements you can't hold them
responsible for anything, so good luck....

Neil

----- Original Message -----
From: "Don Weber" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, July 31, 2002 1:27 PM
Subject: OT: Web Messaging Hack (was: RE: [IMail Forum] )


>
> /begin rant
> lemme think, a recall a post on a list somewhere, that involves a person
> that found security hole in hp-ux or something, hp was notified many times
> in apparently a 90 day period, without even bothering to reply to the
> messages, at which point the guy posted to bugtraq or elsewhere, which
> resulted in HP making a claim that they reserve the right to hold the
person
> that released the information responisble for any exploitation that might
> incur as a result. I think after i got threatened in that way a few times,
i
> might use anonymous email addresses as well. it all comes down to what
> exactly is the correct general practice for full disclosure and to what
> degree vendors should be held responsible. especially in a case like this,
> my opinion is that if vendor is notified and ignore such notification, in
> this manner, vendor should without doubt be held responsible, even
> considering that whitehat releases an exploit at some point, if that
exploit
> is used against me, and i know that vendor was notified over 90 days ago,
> yet decided not to take action or even notify me that there may be a
> security hole in a product i purchased from them, I think it is reasonable
> to assume the vendor was negligent and knowingly allowed a product with a
> secutiry hole to breech my network. I think i should be able to hold the
> vendor responsible, but with the way things look, vendors have deeper
> pockets than the whitehats which will likely result in vendors never being
> notified about security holes and those exploits will stay underground.
> vendors should make clear what their policies are on full disclosure, and
> make it even more clear how they handle those that find such holes or
bugs,
> whether or not they will try to make them responsible or if they will
reward
> them for using proper notification procedures, that may help a whitehat,
or
> even blackhat, for that matter, to decide exactly what method they should
> use with that vendor when it comes to disclosing what may have been found.
> /end rant
>
> sorry, just some things that come to mind.
> i'll go have my cofee with lots of sugar now.
>
> Don
>
> > >-----Original Message-----
> > >From: [EMAIL PROTECTED]
> > >[mailto:[EMAIL PROTECTED]]On Behalf Of Dave Salovesh
> > >Sent: Wednesday, July 31, 2002 8:07 AM
> > >To: '[EMAIL PROTECTED]'
> > >Subject: RE: Web Messaging Hack (was: RE: [IMail Forum] )
> > >
> > >
> > >> person reporting. If the person thought it was so important to post
on
> > >> bugtraq, why use such an address?
> > >
> > >If he didn't, we'd all know what Sandy does in his spare time.
> > >
> > >Oops.
> > >
> > >--
> > >Dave Salovesh
> > >RAM Associates, Inc.
> > >(800 or 202) 543-3635
> > >
> > >
> > >Please visit http://www.ipswitch.com/support/mailing-lists.html
> > >to be removed from this list.
> > >
> > >An Archive of this list is available at:
> > >http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
> > >
> > >Please visit the Knowledge Base for answers to frequently asked
> > >questions:  http://www.ipswitch.com/support/IMail/
> > >
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> An Archive of this list is available at:
> http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
>
> Please visit the Knowledge Base for answers to frequently asked
> questions:  http://www.ipswitch.com/support/IMail/
>


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to