Full Disclosure mailing list archives
Re: MS02-065 vulnerability
From: "HggdH" <hggdh () attbi com>
Date: Fri, 22 Nov 2002 13:24:50 -0600
. From: "Paul Szabo" <psz () maths usyd edu au> . To: <bugtraq () securityfocus com>; <full-disclosure () lists netsys com> . Sent: Friday, November 22, 2002 04:36 . Subject: [Full-disclosure] MS02-065 vulnerability . . (...) . . Is this what Microsoft calls "responsible disclosure"? . . (...) Please note they do recognise it, and also state that one should trust *noone*, including Microsoft. Quoting: "What steps could I follow to prevent the control from being silently re-introduced onto my system? The simplest way is to make sure you have no trusted publishers, including Microsoft." I do think this is "responsible disclosure". Even more: I think they did the right thing, when stated it. Would you rather have Microsoft *not* stating it? The only point I think should be made here is that Microsoft should have stated it clear and loud -- perhaps on it's own Security Bulletin. How many people really go and read it? After all, Microsoft is actually saying "do not trust me". The real interesting part, for me, is that the trust on the trusting mechanism has been shattered. Finally. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- MS02-065 vulnerability Paul Szabo (Nov 22)
- Re: MS02-065 vulnerability Georgi Guninski (Nov 22)
- Re: MS02-065 vulnerability HggdH (Nov 22)
- <Possible follow-ups>
- Re: MS02-065 vulnerability Paul Szabo (Nov 23)
- Re: MS02-065 vulnerability HggdH (Nov 23)