« Meetinghouse withdraws from TCG | Main | Friends who blog/podcast »

July 19, 2006

Fire!

One of my favorite blogging/podcasting people, Martin McKeay, posted on his Computerworld blog yesterday, an article about the debate over instant versus responsible disclosure.  This was in addition to a conversation on the Security Roundtable Podcast that we had the other night and will be posted hopefully soon. Martin and I are on opposite ends on this one.  I think that instant disclosure in many cases amounts to yelling fire! in a crowded movie theater. What good does it do?  Do you think consumers are going to do something with the information?  Most only know that when Microsoft issues a patch, if they are using WSUS or Windows Update they get a patch.  Using a 3rd party patch is I think playing Russian Roulette.  The only good I can see it doing is maybe putting some pressure on the software vendor to get something out because the public knows about the vulnerability.  However, the other side of that coin is, force them to rush out a patch and quality suffers.

Now don't get me wrong, in my view of responsible disclosure, after a vendor has been made aware of a vulnerability, they should put out a fix in a reasonable time, otherwise it is perfectly OK to announce the hole publicly.  But overall, I think we are all better off if the vendor is given some time to patch or fix the vulnerability before the it is made public knowledge.  I don't believe all hackers know of every vulnerability out there.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200d83429364a53ef

Listed below are links to weblogs that reference Fire!:

» The Daily Incite - July 20, 2006 from Security Incite: Analysis on Information Security
July 20, 2006 Good Morning: Sometimes I feel like the rabbit in Alice in Wonderland: Im late. Im late. For a very important date. You know, those days where you get a lot done, but the pile is probably a bit bigger than when yo [Read More]

Comments

Search

Lijit Search

disclaimer

  • The views and opinions expresed here are those of myself only and in no way represent the views or positions or opinions of my employer, Latis Networks, Inc. d/b/a StillSecure or anyone else.

Blog Networks

  • Find the best blogs at Blogs.com.

StillSecure, After all these years, the podcast

Blog powered by TypePad
Member since 10/2005