Full Disclosure mailing list archives

Organization for Internet Safety (OIS) formally announced


From: guninski () guninski com (Georgi Guninski)
Date: Tue, 01 Oct 2002 14:22:19 +0300

So this is a bunch of companies, now what?
I want to question the credibilty of this bunch.
Everyone can register an .org and claim to be the most important bunch on earth.
According to:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/news/standard.asp
from November 2001
"... @stake, Bindview, Foundstone, Guardent, Internet Security Systems and 
Microsoft announced their intention to form an organization whose purpose will 
be to propose industry standards for handling security vulnerabilities." 
(basically not to disclose 0days)
So what?

Georgi Guninski
http://www.guninski.com

Steven M. Christey wrote:
For those of you who care about vulnerability disclosure issues, the
"Organization for Internet Safety" (OIS) formally announced its
existence.  This is the same group of security and software companies
that has been discussed in past months.

The founding members are: @stake, BindView, Caldera International (The
SCO Group), Foundstone, Guardent, ISS, Microsoft, NAI, Oracle, SGI,
and Symantec.

Note that my employer, MITRE, is not a member of OIS.  This often
causes confusion because I have been involved in writing documents
that OIS may use as part of their own policies.

Some articles are at:

  http://www.theregister.co.uk/content/55/27312.html

  http://www.eweek.com/article2/0,3959,558881,00.asp

The OIS home page is at:

  http://www.oisafety.org

A FAQ is at:

  http://www.oisafety.org/about.html


The FAQ should be of high interest to anybody who does vulnerability
research.

- Steve
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html






Current thread: