[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] Rate Stratfor's Incident Response



On Fri, 13 Jan 2012 10:37:31 -0600
Paul Schmehl <pschmehl_lists@xxxxxxxxx> wrote:

> --On January 12, 2012 3:16:19 PM -0500 Benjamin Kreuter 
> <ben.kreuter@xxxxxxxxx> wrote:
>
> > The law is not going to stop the really bad people
> > from attacking your system, nor is it going to stop them from
> > profiting from whatever access they gain; sending law enforcement
> > after someone who reports problems to you accomplishes little and
> > only discourages people who might try to help you.
> >
> 
> Assuming everyone's motives are as pure as the driven snow is a bit
> naive, don't you think?

Are there lingering doubts about the motives of someone who is
reporting a vulnerability to you?  They could have just profited from
their discovery and never bothered to tell you.  In any case, what have
you accomplished by sending the cops after *someone who is helping you*?

-- Ben

> -- 
> Paul Schmehl, Senior Infosec Analyst
> As if it wasn't already obvious, my opinions
> are my own and not those of my employer.
> *******************************************
> "It is as useless to argue with those who have
> renounced the use of reason as to administer
> medication to the dead." Thomas Jefferson
> "There are some ideas so wrong that only a very
> intelligent person could believe in them." George Orwell
> 
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
> 


-- 
Benjamin R Kreuter
UVA Computer Science
brk7bx@xxxxxxxxxxxx

--

"If large numbers of people are interested in freedom of speech, there
will be freedom of speech, even if the law forbids it; if public
opinion is sluggish, inconvenient minorities will be persecuted, even
if laws exist to protect them." - George Orwell

Attachment: signature.asc
Description: PGP signature

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/