<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Marketing for security companies now via Secunia!</title>
	<link>http://blog.assarbad.net/20061119/marketing-for-security-companies-now-via-secunia/</link>
	<description>Programming, reverse engineering and anything else as well ...</description>
	<pubDate>Sat, 11 Oct 2008 19:36:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Oliver</title>
		<link>http://blog.assarbad.net/20061119/marketing-for-security-companies-now-via-secunia/#comment-36003</link>
		<dc:creator>Oliver</dc:creator>
		<pubDate>Tue, 11 Mar 2008 01:12:43 +0000</pubDate>
		<guid>http://blog.assarbad.net/20061119/marketing-for-security-companies-now-via-secunia/#comment-36003</guid>
		<description>Very good question. I am sure it will be possible to find a modus operandi. However, this method sounds more like blackmail:

&lt;blockquote&gt;We know there is a vulnerability and we'll tell everyone in a very abstract way that there is one - however, we'll only disclose details if you pay us.&lt;/blockquote&gt;

Basically it is a service no one asked you to do, so the question who has to pay and why is a very good question indeed.

However, I see that there is another problem. That is, that many vendors don't consider security holes a threat. Either it results in a very relaxed handling of such vulnerabilities, the bugs being ignored or the PR department "trying to contain" the damage.

// Oliver</description>
		<content:encoded><![CDATA[<p>Very good question. I am sure it will be possible to find a modus operandi. However, this method sounds more like blackmail:</p>
<blockquote><p>We know there is a vulnerability and we&#8217;ll tell everyone in a very abstract way that there is one - however, we&#8217;ll only disclose details if you pay us.</p></blockquote>
<p>Basically it is a service no one asked you to do, so the question who has to pay and why is a very good question indeed.</p>
<p>However, I see that there is another problem. That is, that many vendors don&#8217;t consider security holes a threat. Either it results in a very relaxed handling of such vulnerabilities, the bugs being ignored or the PR department &#8220;trying to contain&#8221; the damage.</p>
<p>// Oliver</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: van</title>
		<link>http://blog.assarbad.net/20061119/marketing-for-security-companies-now-via-secunia/#comment-35997</link>
		<dc:creator>van</dc:creator>
		<pubDate>Tue, 11 Mar 2008 00:58:06 +0000</pubDate>
		<guid>http://blog.assarbad.net/20061119/marketing-for-security-companies-now-via-secunia/#comment-35997</guid>
		<description>well,
Discovering bugs is tedious. Who will pay for if we accept the full-disclosure policy?</description>
		<content:encoded><![CDATA[<p>well,<br />
Discovering bugs is tedious. Who will pay for if we accept the full-disclosure policy?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: reyortsed</title>
		<link>http://blog.assarbad.net/20061119/marketing-for-security-companies-now-via-secunia/#comment-84</link>
		<dc:creator>reyortsed</dc:creator>
		<pubDate>Mon, 20 Nov 2006 12:19:50 +0000</pubDate>
		<guid>http://blog.assarbad.net/20061119/marketing-for-security-companies-now-via-secunia/#comment-84</guid>
		<description>Nice one Secunia. Lets just report the world as a bug?

I can see it now...

"GLEG have discovered an potential undefined bug in an unknown software by an unknown company that could potentially be used to comprimise the system in an unspecified way"

Solution: "Build a time machine, go back in time and prevent software and computers from EVER being invented"...

I agree with the author of this blog, this is insane... that you seem to have to buy their software to get the info... as the author says full disclosure is FULL disclosure... come on Secunia, wipe that crap of your site!!!</description>
		<content:encoded><![CDATA[<p>Nice one Secunia. Lets just report the world as a bug?</p>
<p>I can see it now&#8230;</p>
<p>&#8220;GLEG have discovered an potential undefined bug in an unknown software by an unknown company that could potentially be used to comprimise the system in an unspecified way&#8221;</p>
<p>Solution: &#8220;Build a time machine, go back in time and prevent software and computers from EVER being invented&#8221;&#8230;</p>
<p>I agree with the author of this blog, this is insane&#8230; that you seem to have to buy their software to get the info&#8230; as the author says full disclosure is FULL disclosure&#8230; come on Secunia, wipe that crap of your site!!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
