- TalkBack 5 of 34:
- Next »
- « Previous
- Thread View
- Flat View
- Public dissemination of vulnerabilities
-
Anyone who openly provides exploit code should be legally responsible for the effects. If a worm using the exploit produces $1 billion worth of damage, the one who published the code should be reimbursing the cost from prison earnings for, say, 20 years.
Anyone who openly publishes a vulnerability in such detail that the problem can be found and used easily for malware should be subject to only slightly less severe penalties.
In my view, someone who produces or contributes to the production of malware should be subject to penalty. The motive for the crime and the amount of money received by the perpetrator are not relevant to the severity of the offense.
That said, the problem of how to compel a response by the company which has produced the vulnerability remains. A solution has to be found which does not jeopardize millions of innocents and billions of dollars.
Responsible people in the security field and the companies appear to be approaching a solution, but from the article the people identifying vulnerabilities still observe a disproportion in power between themselves and the companies which must act to prevent flaws.
Analogous to a regulator, there should be a prominent security organization which can get headlines by announcing a substantial flaw. Some government agencies have allready shown how prominent such announcements can become.
Public complaints by respected people can have an effect where it's most important to a company, in sales and product use.
Let's limit the damage to the company which is being lax about a vulnerability, rather than punishing such companies by damaging many people who have no responsibility for the situation. - Posted by: Anton Philidor Posted on: 08/17/06 You are currently: a Guest | Members login | Terms of Use
What do you think?
SponsoredWhite Papers, Webcasts, and Downloads
- Virtualization: Architectural Considerations And Other Evaluation Criteria VMware Of the many approaches to x86 systems virtualization available in the ... Download Now
- Key Strategies for Federal Agencies - Safe and Cost Effective Migration for Legacy Hardware GovConnection The federal government has mandated that federal agencies reduce energy ... Download Now
- Why Isn't Server Virtualization Saving Us More? A Few Small Changes May Dramatically Increase Your Efficiency VMware Companies have rapidly adopted server virtualization over the past few ... Download Now
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Learn more about tools to grow your business
-
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
- Save time with the UPS Business Essentials Guide
- The best support in the Linux business
-
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.

- Learn more >>
- Keep Up With The Latest In Document Management with The DocuMentor.
-
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
- Learn more >>
- Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
-
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.

- Learn more about the free, six-month trial offer >>
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- How to Drive Better Business Outcomes with Exceptional Web Experiences Download the eBook
- Driving Business Agility through SOA Connectivity & Integration Read the White Paper from IBM
- Linking Decisions and Information for Organizational Performance Read the Tom Davenport study








