RE: Re[2]: [VulnDiscuss] Cybersecurity, Research & Disclosure Conference

"Mike Fratto" <[email protected]> Fri, 7 Nov 2003 08:56:19 -0500
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <000d01c3a536$ec566d90$020aa8c0@bitchin>
 
> > Perhabs there's so few active independent security 
> researchers because 
> > they are busy actively researching instead of trying to shape an 
> > ethical code governing the right way others should go about their 
> > lives.
> 
> Actually the OIS process was shaped by the practices of 
> hundreds of security researchers and dozens of vendors.  Look 
> at the thousands of issues disclosed last year and you will 
> find that most follow the spirit of the OIS process.

Are you really trying to make the claim, Chris, that because many
researchers choose to follow a model of notifying vendors of vulns that the
behavior is solely attributable to OIS? That's quite a stretch. Come on.
RFPpolicy was around long before OIS and the topic of full disclosure was
hardly brought to the table by OIS. Perhaps it was the creation of RFPpolicy
and all the discussion that ensued that spawned all the vendor disclosure?

mike