7 new IE holes

capybara

Senior member
Jan 18, 2001
630
0
0
internet exploDer has security problems ? but its made by m$ and they wouldnt release anything with security problems !
 

MrChad

Lifer
Aug 22, 2001
13,507
3
81
The discovery of the holes was not reported directly to Microsoft but was announced on public mailing lists, a move the Microsoft spokesman criticized.

I have to agree with Microsoft's criticism here. Some of these security groups and researchers seem more intent on embarassing Microsoft than helping them (and their users) resolve the security flaws they have. Why not just quietly report the issue to Microsoft so that they can fix it before it becomes more widely known? How does announcing a security flaw on a public mailing list benefit anybody?
 

MadAd

Senior member
Oct 1, 2000
429
1
81
ahh well thats the age old argument about security by obscurity vs full (and timely) disclosure expecially now that the security organisations in general are more mature and have their own agendas (eg information only for those that pay yadda ya) basicly leaving the rest of us in the dark.

Quote:To summarize my opinion, I feel that security information must simply be
made available to as many people as possible as quickly as possible, and
let corporations, systems staff, and security professionals handle the
problems. "The public has a right to know.." and any comparisons to
dislosing national security technology to the full disclosure of software and
network security problems should be totally ignored as they simply don't
apply.

(taken from http://www.deaddrop.org/LenRose.html)
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
How does announcing a security flaw on a public mailing list benefit anybody?

It gives people a chance to stop using IE until the problems are fixed, if only MS and a few random people on the Internet know about it there's a chance something could be put in the wild before the patches are released and noone will know how they got hit. Atleast if the problems are public they'll know and can work around them until MS gets something done.