Secure Coding mailing list archives

Economics of Software Vulnerabilities


From: coley at linus.mitre.org (Steven M. Christey)
Date: Wed, 21 Mar 2007 16:39:47 -0400 (EDT)


I was originally going to say this off-list, but it's not that big a deal.

Arian J. Evans said:

I think you are on to something here in how to think about this subject.
Perhaps I should float my little paper out there and we could shape up
something worth while describing how the industry is evolving today.

I've been wanting to do something along these lines but don't have much
time.  I'll gladly review it or provide suggestions.  I have a draft on
current disclosure practices that includes the diversity of researchers
and the role of vulnerability information providers.

- Steve


Current thread: