On CBS.com: You a Race Fan?Play Amazing Race Fantasy
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 1 of 18:
Next »
Cisco & ISS should remove the gag
"Cisco on Friday released a security advisory detailing the flaw in IOS that was exposed by Lynn and admitting that it could be exploited to gain control over routers. "

If he hadn't released that information we wouldn't know that CISCO had a known security hole, and customers couldn't have avoided their routers until they fixed it. ISS and Cisco should remove the gag, so we can see the full extent of the problem, rather than the spun PR version.

I wonder if this doesn't mean a change on how security holes are reported though.

The past:
Security holes reported immediately. Companies scramble to fix them.

The present:
Security holes are kept secret for a courtesy period. Companies fix them (or not in this case). Information is released.

But don't companies have a duty to disclose all material matters to their shareholders? If there's a known fault in your main product then thats a pretty big deal don't you think? Something the shareholders should know about? Yet they had a 27th May 10Q that doesn't mention it.

I wonder if the future isn't:

Mandatory disclosure of security holes in non detail terms. Fix. Detail disclosure. i.e. that companies will have to disclose these security holes themselves promptly to their shareholders, without giving the details.
Posted by: Nigel Johnstone   Posted on: 07/30/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Cisco & ISS should remove the gag  Nigel Johnstone | 07/30/05
And if ISS hadn't hired him?  __howard__ | 07/30/05
Theft of Research  __howard__ | 07/30/05
Not theft, whistleblowing  Nigel Johnstone | 07/30/05
The researcher committed theft (or possibly emezzlement)  __howard__ | 07/30/05
Researcher wasn't CISCO employee, not a whistleblower  __howard__ | 07/30/05
Whistleblower doesn't have to be employee  Nigel Johnstone | 07/30/05
Embezzlement might be a better word than theft.  __howard__ | 07/30/05
Read on down  Nigel Johnstone | 07/30/05
Intellectual Property Can Be Misappropriated (Stolen)  __howard__ | 07/30/05
Doesn't follow  Nigel Johnstone | 07/30/05
I've sited multiple sources ...  __howard__ | 07/30/05
Benefits  Nigel Johnstone | 07/30/05
Marxist concept that only manual labor has value & not products of the mind  __howard__ | 07/30/05
Seems you are correct  Nigel Johnstone | 07/31/05
The real crime in all of this is cisco  bjbrock | 07/30/05
real crime  longrider_z | 07/30/05
It's more than the inside.  duckie37 | 08/02/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here