On mySimon: Joovy Caboose Ultralight Sunset
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 22 of 34:
Next »
« Previous
Producing responses
If a I, as a bug hunter, find a flaw, how do I get the manufacturer to do something? If I dump my findings on the internet, I'm a bad boy. If I'm a good boy and contact the manufacturer, I'm told to wait until they have a patch. At this point how do I get the manufacturer to do anything? How long is it reasonable to wait?

I know a little about the politics of fixing bugs. There is always something more important to do than fix this bug. How many times and from how many vendors have we all heard "It's a known problem, don't do that."

Give the manufacturer 30 days then publish. If they can't get it fixed in that time, then they need to contact me and try to convince me to extend for another 30 days. Second time they call, convice me again.

But how many times do I delay? I know some problems are much easier to say than they are to fix. I know some problems are a matter of adding, removing, or replacing a single character. Most of the time is comes down to getting approval to spend the time and make the fix.

I wish there were simple answers to this question. Hell, I'd take a complex answer.
Posted by: dmhunter@...   Posted on: 08/17/06 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Its the  not of this world | 08/17/06
I agree;  Suicida| | 08/17/06
Cheap way to find flaws  SteveTheWirePuller | 08/17/06
Valid concerns from true flaw finders  Boot_Agnostic | 08/17/06
Public dissemination of vulnerabilities  Anton Philidor | 08/17/06
A problem...  ju1ce | 08/17/06
Why would the idea fail?  Anton Philidor | 08/17/06
well it can...and it can't..  Monkey_MCSE | 08/17/06
another question...sorry  Monkey_MCSE | 08/17/06
The organization's purpose...  Anton Philidor | 08/17/06
And...  Anton Philidor | 08/17/06
and how many years did it take them??  Monkey_MCSE | 08/17/06
If no alternative operating systems...  Anton Philidor | 08/18/06
Fair's fair  Yagotta B. Kidding | 08/17/06
Flaw finders to software makers: It's payback time  puppadave | 08/17/06
IF THERE'S ANYTHING WRONG WITH A COMPUTER OR SOFTWARE IT'S A VIRUS !  BALTHOR | 08/17/06
Message has been deleted.  Colonel Panijk | 08/18/06
Flaw Finders  eryxias7@... | 08/17/06
What's the limit?  rpmyers1 | 08/18/06
No respect  shraven | 08/17/06
Last thing vendors want: explaining changes to outsiders  ejhonda | 08/17/06
Producing responses  dmhunter@... | 08/17/06
Bad headline  John L. Ries | 08/17/06
Shakedown  DaveSoNSo | 08/17/06
That's called "blackmail"  John L. Ries | 08/18/06
Ignorance is bliss, ay?  Tialin | 08/17/06
Well...  Anton Philidor | 08/17/06
Inconsistent expectations  DaveSoNSo | 08/17/06
When I pay for Software I Expect it to Work  OldTimer1 | 08/21/06
It's always Microsoft  AAWW | 08/17/06
I wouldn't say most flawed...  jasonp@... | 08/18/06
software flaws  jhinkson@... | 08/17/06
Not likely....  Leria | 08/18/06
Unlikely but possible  tony@... | 08/18/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement
  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More