Linked by Thom Holwerda on Thu 18th Jan 2007 21:38 UTC, submitted by Ricus
Privacy, Security, Encryption "Security, perception, reality. What security professional hasn't struggled with the gaps between those three things? Is there anything worse for security than a false sense of security?" And part II.
Thread beginning with comment 203282
To read all comments associated with this story, please click here.
disappointing article
by david-craig on Fri 19th Jan 2007 00:09 UTC
david-craig
Member since:
2007-01-18

I was very disappointed with this article as it seems to demonstrate the typical atittude of lazy reporting often seen in IT blogs posing as journalism.

Part one disparaged Secunia's reporting of vulnerabilites asking the reader to return later for the evidence. Part one seemed like little more than an advertisement for part two.

While promised that part two would "explore methods for getting an accurate view of publicly disclosed, but unpatched vulnerabilities in products on any given day or over periods of time", I found no such exploration. I did find another adverisment for "a paper" that is being written.

However, the element that most annoyed me was the lack of evidence to support the accusations regarding Secunia's database. Rather than evaluating a large number of possible vulnerabilities that may have effected a number of different products and compairing them against the information provided by Secunia, one product and one exploit is examined. The result of this examination is that the product *might* have been effected by it. In other words, the author has no evidence whatsoever.

What I find most frustrating is that the author may very well be correct in his assumptions. He failed, however, to do the necessary work to prove (or even present a reasonable level of supporting information to back up) his claims.

RE: disappointing article
by flanque on Fri 19th Jan 2007 01:05 in reply to "disappointing article"
flanque Member since:
2005-12-15

I agree. That'd constitute too much effort for a blogger.

Edited 2007-01-19 01:06

Reply Parent Bookmark Score: 4

RE: disappointing article
by sbergman27 on Fri 19th Jan 2007 01:06 in reply to "disappointing article"
sbergman27 Member since:
2005-07-24

"""I was very disappointed with this article as it seems to demonstrate the typical atittude of lazy reporting often seen in IT blogs posing as journalism."""

Bravo! I, too am growing weary of this "anyone can be a journalist and all you need is a web host and some blog software and a good solid gripe against someone" world. I'm even more weary of the "news" sites that seem to consider the resultant editorial tripe posing as real journalism to be newsworthy.

If the guy had some real evidence and presented it, that would be great. But suggestion and innuendo intermixed with a bunch of "next week, I'm gonna..." is idle chatter, not news.

Can this guy until he actually has something of substance to report.

Reply Parent Bookmark Score: 4

RE: disappointing article
by jrjones on Fri 19th Jan 2007 20:48 in reply to "disappointing article"
jrjones Member since:
2007-01-19

Gee, you guys have no sense of drama. It's a blog, not an article. It's in 3 parts because I a) work on it in my spare time, and b) didn't want a single post to be too long.

Anyway, Part 3 is up and does have charts/numbers, as some folks have asked for.

http://blogs.technet.com/security/archive/2007/01/19/exposed-examin...

or just http://blogs.technet.com/security

Jeff

Reply Parent Bookmark Score: 1