RE: Re[2]: [VulnDiscuss] Cybersecurity, Research & Disclosure Conference
Chris Wysopal <[email protected]> Fri, 7 Nov 2003 14:44:37 +0000 (GMT)
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 7 Nov 2003, Mike Fratto wrote: > > Actually the OIS process was shaped by the practices of > > hundreds of security researchers and dozens of vendors. Look > > at the thousands of issues disclosed last year and you will > > find that most follow the spirit of the OIS process. > > Are you really trying to make the claim, Chris, that because many > researchers choose to follow a model of notifying vendors of vulns that the > behavior is solely attributable to OIS? That's quite a stretch. Come on. > RFPpolicy was around long before OIS and the topic of full disclosure was > hardly brought to the table by OIS. Perhaps it was the creation of RFPpolicy > and all the discussion that ensued that spawned all the vendor disclosure? I am saying the OIS process was shaped by researcher practices not the other way around. Of course disclosure policies, ad hoc or formal, were around before OIS. I certainly know about RFPolicy. I contributed to the original version and was an active discloser before and during its creation. -Chris > mike > >