Reply to post:

Clear April 12: Windows, Samba to splat curious 'crucial' Badlock bug

Michael Wojcik Silver badge

I thought there used to be security lists that people subscribed to for this sort of thing

There still are. BUGTRAQ, for example, is still going strong.

is every vulnerability from this point forward going to have a catchy name and a website?

No. While it seems like there are a lot of these "celebrity bugs", they're really a very small fraction of public disclosures. I've received 14 emails from BUGTRAQ today. Even weekly and monthly summaries of only "major" vulnerability announcements, from various CERTs and the like, are almost entirely non-celebrity bugs.

So while we're certainly seeing more of this sort of thing, it's barely at the level of background noise to anyone who follows common vulnerability-disclosure channels.

Personally, I have no objection to the fad. While it's easy to demonstrate how cynical and cool you are by mocking it (hello, Reg scribes!), it makes it much easier to light a fire under management and inform end users. Someone's creating an easy-to-find description of the problem for non-experts? Oh, the horror.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon