SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Technology Stocks : How high will Microsoft fly? -- Ignore unavailable to you. Want to Upgrade?


To: Ramsey Su who wrote (24370)6/18/1999 2:16:00 PM
From: ericneu  Read Replies (1) | Respond to of 74651
 
This article was discussed in this morning's San Diego Union. Can anyone comment how significant it may be?

Ramsey
---

Looking at it from a technical point of view, it's significant, but not necessarily any more so than previous security issues. A workaround was publicized the day eeye went public, and a patch is now available.

The most interesting issue here (IMHO) is not the security issue, but eeye's handling of it. It's common practice in the security industry to inform the vendor quietly of the vulnerability, and not publicize the issue until after a patch is available. Not only did eeye widely publicize the issue, they created a program specifically to attack the vulnerability and then posted it to their website.

Pretty strange behavior - makes me wonder what axe they're grinding. Oh, wait a minute - they sell security software. Free publicity. Hmm. :)

- Eric