Full Disclosure mailing list archives
Re: it\'s all about timing
From: full-disclosure () lists netsys com (Steven M. Christey)
Date: Mon, 5 Aug 2002 21:23:13 -0400 (EDT)
"Robert A. Seace" <ras () slartibartfast magrathea com> said:
3.3.1 Vendor Responsibilities 7) The Vendor SHOULD recognize that inexperienced or malicious reporters may not use proper notification, and define its own procedures for handling such cases.Why must they automatically be labelled either "inexperienced" or "malicious", if they don't choose to follow the chosen guidelines?? Suppose they simply disagree with those guidelines? They may feel it's not THEIR job to spend a large portion of their time trying to educate the vendor about their own broken software... ... if you're still modifying this "policy", I would really suggest changing that language... Just drop the whole labelling of such people, and simply say something like, "Some reporters may not follow these guidelines for notification."...
Good point, duly noted. Many of the items in the draft try to give a rationale for why the item is there. In this case, the rationale is mixed with the recommendation, and as you point out, it's incomplete anyway. There are a number of reasons why someone may not use "proper" notification. Thanks, - Steve
Current thread:
- Re: it\'s all about timing, (continued)
- Re: it\'s all about timing full-disclosure () lists netsys com (Aug 02)
- Re: it\'s all about timing Steven M. Christey (Aug 02)
- Re: it\'s all about timing Robert A. Seace (Aug 02)
- Re: it\'s all about timing Ron DuFresne (Aug 02)
- Re: it\'s all about timing full-disclosure () lists netsys com (Aug 02)
- Re: it\'s all about timing full-disclosure () lists netsys com (Aug 02)
- Re: it\'s all about timing full-disclosure () lists netsys com (Aug 02)
- Re: it\'s all about timing full-disclosure () lists netsys com (Aug 05)
- Re: it\'s all about timing Steven M. Christey (Aug 05)
- Re: it\'s all about timing Steven M. Christey (Aug 05)
- Re: it\'s all about timing Steven M. Christey (Aug 05)
- Re: it\'s all about timing Steven M. Christey (Aug 05)
- Re: it\'s all about timing Steven M. Christey (Aug 05)
- Re: it\'s all about timing Ron DuFresne (Aug 05)
- Re: it\'s all about timing full-disclosure () lists netsys com (Aug 07)
- Re: it\'s all about timing full-disclosure () lists netsys com (Aug 07)
- Re: it\'s all about timing full-disclosure () lists netsys com (Aug 07)
- Re: it\'s all about timing full-disclosure () lists netsys com (Aug 07)