OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] Right, or wrong?

Valdis.Kletnieksvt.edu
Date: Wed Aug 08 2007 - 12:24:38 CDT


On Wed, 08 Aug 2007 10:34:03 EDT, Byron Sonne said:
> > Is it morally right, wrong, don't know, don't care, good business, bad
> > business, etc.? Either way we're moving away from that model, but I was
> > just curious how others on FD see it.
>
> It's lame, as I see it. IMO, as soon as a bug/vuln is found it should be
> released into the public domain, with as wide a circulation as possible,
> and free of charge.
>
> This way as much damage, mischief and chaos as possible can be sown.

Would you still feel that way if the resulting worm took out your bank's
ATM network, and as a result you couldn't get to your money? Or if your
identity got stolen and you found yourself liable for $4,000 of credit
card or cell-phone charges?

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFGufxWcC3lWbTT17ARAmMwAJ9qd4XviayXwf2FfjVnWgtQkX1v4wCg2aXW
iXjEVhz9+/R2XIOg95fev2M=
=1QJ7
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/