<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Flaws,exploits and zero-days should they be kept secret?&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Flawsexploits-and-zerodays-should-they-be-kept-secret-23306191</link>
<description></description>
<language>en</language>
<pubDate>Fri, 10 Feb 2012 14:24:17 EDT</pubDate>
<lastBuildDate>Fri, 10 Feb 2012 14:24:17 EDT</lastBuildDate>

<item>
<title>Re: Flaws,exploits and zero-days should they be kept secret?</title>
<link>http://www.dslreports.com/forum/Re-Flawsexploits-and-zerodays-should-they-be-kept-secret-23306429</link>
<description><![CDATA[nwrickert posted : The best practice, as far as I can tell is:<br><br>Immediately notify the developers of the affected software.  Ideally, the developers will start working on a solution.<br><br>Notify the general public when any of the following have occurred:<br> (a) the developer has an effective solution that is ready to be put in place;<br> (b) information on the flaw has already leaked, so the public needs to be warned;<br> (c) substantial time has passed, the developer does not seem to be working on the problem, and publication is the only way to put pressure on the developer.<br><br>It is my impression that such practices are already followed by many.<br><small>--<br>AT&T Uverse; Zyxel NBG334W router (behind the 2wire gateway);  openSuSE 11.0; firefox 3.0.15</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Flawsexploits-and-zerodays-should-they-be-kept-secret-23306429</guid>
<pubDate>Sat, 07 Nov 2009 13:26:07 EDT</pubDate>
</item>

<item>
<title>Re: Flaws,exploits and zero-days should they be kept secret?</title>
<link>http://www.dslreports.com/forum/Re-Flawsexploits-and-zerodays-should-they-be-kept-secret-23306269</link>
<description><![CDATA[Smokey Bear posted : The question is much to simple, it depend on. Varied factor and circumstances play a role so I can not vote with yes or no. Every flaw/exploit have to be analysed/judged on itself. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Flawsexploits-and-zerodays-should-they-be-kept-secret-23306269</guid>
<pubDate>Sat, 07 Nov 2009 12:43:19 EDT</pubDate>
</item>

<item>
<title>Re: Flaws,exploits and zero-days should they be kept secret?</title>
<link>http://www.dslreports.com/forum/Re-Flawsexploits-and-zerodays-should-they-be-kept-secret-23306248</link>
<description><![CDATA[TearAbite posted : i guess NO:<br>If i find an exploit, that means that all the people that are smarter than me will also find it at some point..  I would notify the manufacturer, give them some time to react (say, 30 days) - THEN publish it (without exact details)..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Flawsexploits-and-zerodays-should-they-be-kept-secret-23306248</guid>
<pubDate>Sat, 07 Nov 2009 12:36:45 EDT</pubDate>
</item>

<item>
<title>Flaws,exploits and zero-days should they be kept secret?</title>
<link>http://www.dslreports.com/forum/Flawsexploits-and-zerodays-should-they-be-kept-secret-23306191</link>
<description><![CDATA[sharpy merc posted : This is an incredibly two sided argument.<br><br>The YES camp: with the less people who know the easier it is to fix (and pretend it was never there). Point of view<br><br>The NO camp: With the more its published the faster it'll get fixed (sadly many more people will be affected, till it is). attitude<br><br>so whats your take and what camp are you in?<br><br>BTW if an argument makes you change your mind in either direction that would be interesting]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Flawsexploits-and-zerodays-should-they-be-kept-secret-23306191</guid>
<pubDate>Sat, 07 Nov 2009 12:23:07 EDT</pubDate>
</item>

</channel>
</rss>

