Full Disclosure mailing list archives

Re: Microsoft Cries Wolf ( again )


From: "Kristian Hermansen" <this_is_kris () hotmail com>
Date: Tue, 1 Jul 2003 17:08:56 -0400

I agree.  It is not our problem.  The reason is this.  Microsoft would like
to reduce costs.  Fixing bugs in products costs money, and 0-day bugs need
immediate fixes which slow down MS total output ability.  They would like to
see everyone reporting to the vendor first because this saves them money!!!
In this respect, this also allows them to go on writing sloppy code in order
to save a few bucks on every product, thus reducing their overhead.  I don't
want sloppy code.  Let the 0-days fly....maybe MS will start doing extensive
testing to their products before they release it for sale to millions of
customers.  I thought .NET was supposed to fix all this  ;-P

Kris Hermansen


----- Original Message ----- 
From: <dhtml () hush com>
To: <full-disclosure () lists netsys com>
Sent: Tuesday, July 01, 2003 4:01 PM
Subject: Re: [Full-disclosure] Microsoft Cries Wolf ( again )



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

While there is some argument about what makes a vendor un-responsive,
 patch
times in this case are, likely and understandably, quite lengthy.  These
fixes are not trivial to begin with, thanks in no small part to the
incredible number of customers Microsoft has.  As if the literally
millions
of configurations Microsoft software must support weren't enough, think
for
a second about the multiple different character sets its code applies
to.
Even the *DOCUMENTATION* for the patch must be translated into dozens
of
different languages -- no small task with exploitation looming on the
horizon.  However, it is obvious that in this case, the reporter did
not
attempt any contact with Microsoft what-so-ever.

/////////

This is not my problem. I DON'T CARE!

That's your company and you do with it as you see fit. Whether you want
to make 1 million versions of your product in order to grab every possible
market share, so be it.

You'd better be damn sure that what you make works otherwise if you throw
it out there and it breaks, some one has to pay.

Why not make one quality product instead of hundreds of flawed ones?

That's right! It's your company and you do with it as you see fit!
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.3

wkYEARECAAYFAj8B54UACgkQTAj0ZSCgbx4SNQCfaUzCFmsTRgamjmGFSiZ0qA9/m0gA
oJxvhoN3wc7ZgFgEb2QyRVN6b5wi
=35YT
-----END PGP SIGNATURE-----




Concerned about your privacy? Follow this link to get
FREE encrypted email: https://www.hushmail.com/?l=2

Free, ultra-private instant messaging with Hush Messenger
https://www.hushmail.com/services.php?subloc=messenger&l=434

Promote security and make money with the Hushmail Affiliate Program:
https://www.hushmail.com/about.php?subloc=affiliate&l=427
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: