[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Full-Disclosure] No Subject (re: openssh exploit code?)



> -----Original Message-----
> From: Blue Boar [mailto:BlueBoar@thievco.com]
> Sent: Tuesday, October 21, 2003 2:19 PM
> To: mitch_hurrison@ziplip.com
> Cc: jasonc@science.org; full-disclosure@lists.netsys.com
> Subject: Re: [Full-Disclosure] No Subject (re: openssh exploit code?)
> 
> mitch_hurrison@ziplip.com wrote:
> > My main point being there is simply no
> > need for the disclosure of exploits.
> 
> English is a funny language.  Based on the rest of your note, I assume
> by "no need", you mean that there's no one forcing you to release your
> exploits, and you see no moral imperitive that says you should, yes?
Or
> do you also mean to say that there is "no need" on the part of others,
> by which I mean that you don't believe that other people can put
> exploits to legal, productive uses?
 
Which makes an even better point:  if there is 'no need' to disclose
exploits, what are you doing on a full disclosure list in the first
place?

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html