SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Technology Stocks : How high will Microsoft fly?
MSFT 479.20+0.2%Jan 9 9:30 AM EST

 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext  
To: dybdahl who wrote (66528)3/30/2002 11:32:24 AM
From: David Howe  Read Replies (1) of 74651
 
<< but working on WHEN to report them seems quite untrustworthy to me. Does anybody on this thread know if this is true? >>

Of course it's true and of course there are circumstances where a security issue should be reported later rather than immediately.

If MSFT discovered a security hole in one of ORCL's programs they should report it to ORCL, not the general public. Then, ORCL should take a few days to develop a patch. Then, and only then should they report the problem to the general public. Why tell the hackers how to hack when there isn't a patch available. Delaying the report until the patch is available is the responsible thing to do.

Developing rules and guidelines for this type of thing is important and that is why they are working on it.

IMO,
Dave
Report TOU ViolationShare This Post
 Public ReplyPrvt ReplyMark as Last ReadFilePrevious 10Next 10PreviousNext