Big vendors get deadline to fix holes, or face the music
TippingPoint has upped the ante on vulnerability disclosure by giving vendors six months to fix bugs before it goes public with information on flaws. The intrusion prevention specialist, bought by HP earlier this year, has rewarded security researchers for information about vulnerabilities via its long-running Zero Day …
for real?
"Rushing security fixes may therefore work against the wider interest of end-users, Microsoft argues."
Yeah because we all know that security through obscurity is the way to go!
So how does this work?
"Rushing security fixes may therefore work against the wider interest of end-users, the company argues."
Dear Abby,
Recently I discovered an issue with the software that controls the security system used by the Steve Ballmer and many other captains of industry that lets almost anyone walk around their houses when they are away on vacation. I notified the security system manufacturer a year ago but they still haven't fixed the problem... should I tell Steve and his friends?
Six Months???????????????????????
I would feel generous giving them 6 WEEKS, 6 months is beyond ridiculous.
6 weeks, no action, full disclosure to the world. That should stimulate them to get it patched.
Sign up, sign up for The Register's weekly IT security newsletter - click here
Popular Whitepapers
- The BI Inflexion Point
Information is a right, not a privilege - VPN security - if you want it, come and get it
Attention WiFi hotspotters: You want it - The Register Guide to iSCSI
A primer on Internet SCSI, a protocol to transport SCSI commands over IP - Secure Mobile Working
Beyond the Technology - The Impact of IT Security Attitudes
Putting the pieces in place for effective security delivery - The Register guide to unified communications
A primer on the implications of unified communications for enterprise IT


