Linked by Thom Holwerda on Fri 20th Mar 2009 13:51 UTC, submitted by google_ninja
Thread beginning with comment 354184
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 06/20/13 6:17 UTC, submitted by MOS6510
Linked by Thom Holwerda on 06/19/13 23:02 UTC, submitted by M.Onty
Linked by Thom Holwerda on 06/19/13 22:28 UTC
Linked by Thom Holwerda on 06/18/13 22:33 UTC
Linked by Anonymous on 06/18/13 22:26 UTC
Linked by Thom Holwerda on 06/18/13 22:25 UTC
Linked by Thom Holwerda on 06/18/13 17:45 UTC
Linked by Thom Holwerda on 06/18/13 17:32 UTC, submitted by poundsmack
Linked by Thom Holwerda on 06/17/13 17:58 UTC
Linked by Thom Holwerda on 06/17/13 17:52 UTC
More News »
Sponsored Links



Member since:
2007-09-06
He sat on the vuln for a year intentionally saving it for this competition. How many criminals found that same vulnerability in that time? How many users where left hanging unknowingly. Not even a bug report.
Wanting monetary return is one thing; we all have to eat. That suggests approaching the relevant company in a timely manner though. We want companies to view vulns and issue a patch the day after they are notified of it but that has to go both ways. This is starting to sound like Microsoft business strategy; release the "innovations" as slow as you can to maximize shareholder profits rather than user benefits... booo..
No doubt he's smarter than me but I think the enthusasm with which he's pushing to be paid and the decision to leave users vulnerable for a money shot perl necklace is in bad taste.
Come on Sec devs, those of us in infosec that don't do Dev work are out here mitigating when we could have patched long ago and had safer users.