<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Pros &#x26; cons of publishing security vulnerabilities in </title>
<link>http://www.dslreports.com/forum/r14092773</link>
<description></description>
<language>en</language>
<pubDate>Tue, 01 Dec 2009 00:42:20 EDT</pubDate>
<lastBuildDate>Tue, 01 Dec 2009 00:42:20 EDT</lastBuildDate>

<item>
<title>Pros &#x26; cons of publishing security vulnerabilities</title>
<link>http://www.dslreports.com/forum/remark,14092773</link>
<description><![CDATA[<A HREF="/useremail/u/594412"><b>TKJunkMail</b></A> : &raquo;<A HREF="http://www.eweek.com/article2/0,1895,1843819,00.asp" >www.eweek.com/article2/0,1895,1843819,00.asp</A><br><div class="bquote">The security research company responsible for discovering a software hole later used by the Slammer worm is <B>considering an end to its policy of publishing details of vulnerabilities to public forums</B>.<br><br>Speaking with eWEEK at the Black Hat conference here last month, David said that <B>arguments in favor of disclosing details of software holes have lost force in recent years.</B> At the same time, the threats to organizations and individuals on the Internet from organized cyber-crime syndicates and international terrorists have increased.<br><br>In the wake of the Slammer worm, NGS changed its disclosure policy. NGS now <B>notifies companies of the holes it discovers and gives them time to create a patch and 90 days to distribute it before releasing vulnerability details to the public.</B></DIV>It seems that NGS has reached a reasonable compromise. If they discover a vulnerability, they give the vendor time to fix it <B>and deploy it</B> before using the club of public disclosure on recalcitrant vendors.<br><br>They thereby minimize the possible risk of allowing hackers to unleash an exploit on the public prior to a fix being deployed due to premature disclosure. But they also hold the vendor's feet to the fire by keeping the option of public release available in their back pocket.<br><SMALL>--<br><A HREF="http://tinyurl.com/a9o7w"><B>My Web Page</B></A><BR><A HREF="http://tinyurl.com/5eurx"><B>Join Red Room Forum</B></A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14092773</guid>
<pubDate>Tue, 09 Aug 2005 08:22:29 EDT</pubDate>
</item>

</channel>
</rss>
