I think it was this same MS post that generated an uproar amongst the security community not so long ago. Microsoft is essentially arguing for security through obscurity (don't tell anyone and they won't know) whereas the security geeks were arguing that when security holes are found the responses from the companies involved are often very slow to non-existent unless given a prod with a sharp stick i.e. release exploits to show where and how the vulnerabilities exist.
The general course of events is... find a hole, notify company, nothing happens, release code and info to community, company freaks, patch is issued, repeat... See the following story for a good example of MS at work... <http://www.newsbytes.com/news/01/172878.html> Or for more check the Slashdot thread... <http://slashdot.org/article.pl?sid=01/12/11/2125224&mode=thread> > Another Gaping Microsoft Security Hole Goes UnpatchedPosted by michael on > Tuesday December 11, @10:09PM > from the how-many-times-will-it-take dept. > Newsbytes has a story about a critical vulnerability in all recent versions of > Internet Explorer, which leaves your computer completely open any time you > browse the web with IE. Microsoft has known about it since November 19; they > refuse to provide any information about when a patch might be made available, > if ever. This bug has been successfully handled by Microsoft's "Security > through Obscurity" policies - since there's no public notice, Microsoft has no > need to actually patch this hole which renders several hundred million > computers vulnerable any time they access a web page or parse an HTML email. Cheers Troy. Ray Forma on 13/12/01 5:06 PM, wrote: > It's Time to End Information Anarchy > > By Scott Culp > October 2001 > > If we can't eliminate all security vulnerabilities, then it becomes all the > more critical that we handle them carefully and responsibly when they're > found. Yet much of the security community handles them in a way that fairly > guarantees their use, by following a practice that's best described as > information anarchy. This is the practice of deliberately publishing explicit, > step-by-step instructions for exploiting security vulnerabilities, without > regard for how the information may be used. > > The relationship between information anarchy and the recent spate of worms is > undeniable. Every one of these worms exploited vulnerabilities for which > step-by-step exploit instructions had been widely published. But the evidence > is more far conclusive than that. Not only do the worms exploit the same > vulnerabilities, they do so using the same techniques as were published - in > some cases even going so far as to use the same file names and identical > exploit code. This is not a coincidence. Clearly, the publication of exploit > details about the vulnerabilities contributed to their use as weapons.

