> I am not particularly troubled by his actions, nor do I have any illusions
> about security - but I don't appreciate the manner in which this
information
> was publicized.
Gary, you and I are in complete agreement about this part: I don't like
being slapped in the face either with something that just increases my
potential risk factors. However, we face this all the time. For example
every day, it seems NTBugTraq sends out a new message fully describing some
new NT or NT app exploit. If the software vendor is willing to correct, the
alert contains info about the fix or patch. So my reaction may first be:
"oh sh**, now I've got a problem" (if the exploit is relevant to me)
followed by "ok, here's what I need to correct". If there is no resolution
from the ISV, then maybe what I need to do is move on to another product.
Besides, I know a few cracker types. They don't need to see how to do the
exploit. Once they hear that so-and-so (they all know each other) did it in
less than 8 hours, they will figure out how to do it in less than 6 hours.
>
> Lastly, I happen to think this is a worthwhile discussion, even if some
> folks want to put a dagger in it.
Killing a topic like this is like burying your head in the sand. We, as end
users of someone's product often get complacent, and hope that something
works, or hope that something broken gets fixed. I bet in many cases the
ISV is hoping that its customers don't find known bugs, and hoping that if
they do not too many will complain.
I don't think I'm the only one backing Mike up for describing the problem,
but if I am, I'll shut my mouth.
-phil.
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.