Linked by Thom Holwerda on Tue 28th Jun 2011 22:16 UTC
Permalink for comment 479019
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/21/13 15:53 UTC
Linked by Thom Holwerda on 05/20/13 22:43 UTC
Linked by Thom Holwerda on 05/20/13 21:50 UTC
Linked by Thom Holwerda on 05/19/13 23:15 UTC
Linked by Thom Holwerda on 05/19/13 23:11 UTC, submitted by Drumhellar
Linked by Thom Holwerda on 05/18/13 21:06 UTC
Linked by Thom Holwerda on 05/18/13 7:37 UTC
Linked by fran on 05/18/13 1:38 UTC
Linked by Thom Holwerda on 05/17/13 23:35 UTC, submitted by kragil
Linked by MOS6510 on 05/17/13 22:22 UTC
More News »
Sponsored Links



Member since:
2006-07-14
A thousand times: YES. Time and time again, companies have shown they will not fix security issues unless they are disclosed or threatened to be exposed. Security researchers are not the only ones that look for exploits. In fact most exploits are found after they have been exploited ( without any public disclosure by a security researcher). The public disclosure ensures that all stake holders have a better idea of the risks and can make better business decisions based on that; ie rewarding companies with good security and punishing those without good security.
I know I've posted this a few times here already, but since the same conversation keeps coming up here it is again:
http://www.schneier.com/blog/archives/2007/01/debating_full_d.html
Edited 2011-06-29 05:57 UTC