Re: [VulnWatch] Cisco PSIRT 0 CISCO-SA-20050817

Douglas Duckworth <[email protected]> Wed, 17 Aug 2005 15:50:44 -0500
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
Legally, he did kind of break the "law", however, there is a few
larger ethical questions:

With terrorism, and such, is it ethical for a company to produce
inherently flawed products which are critical to infrastructure?

And, its it ethical for a multimillion dollar corporation to go after
an individual such as Abbadon?

ISS should have done something, yes, that is quite disloyal.  If I was
his employer, I would put up lots of cash; the guy is talented, and
hes going somewhere else now.  I really wonder how the community views
ISS?  I am kind of an amateur, I have no idea, but personally, I would
not work for that kind of corporation.

On 8/17/05, Steve Manzuik <[email protected]> wrote:
> I agree 100%
>=20
> But in this case I think ISS should have stepped up and defended their
> employee.  I do work for an ISS competitor so perhaps I am biased but if
> any of our researchers was presenting something simular to what Lynn was
> we would back him 100% and deal with the vendor threats.
>=20
> I was very suprised to see ISS not do this.
>=20
> On Wed, 17 Aug 2005, Douglas Duckworth wrote:
>=20
> > Lol... its quite sad.  Instead of such actions, they, obviously,
> > should fix the problems in an effort to make their product more
> > secure.
> >
> >
> > That could be asking too much.
> >
> >
> > On 8/17/05, Steve Manzuik <[email protected]> wrote:
> > > Nah, they probably just pressured his employer to hide the details.  =
:P
> > >
> > >
> > >
> > > On Wed, 17 Aug 2005, Douglas Duckworth wrote:
> > >
> > > > Interesting...
> > > >
> > > > I wonder if the individual who found this out got a lawsuit?
> > > >
> > > > -Doug
> > > >
> > > > On 8/17/05, Steve Manzuik <[email protected]> wrote:
> > > > > See the attached text file from Cisco.
> > > > >
> > > > > Cheers;
> > > > >
> > > > > Steve Manzuik
> > > > > Moderator
> > > > > Vulnwatch.org
> > > > >
> > > > >
> > > >
> > >
> >
>