Click here to Skip to main content
15,887,746 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
jschell6-Nov-12 9:09
jschell6-Nov-12 9:09 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
vaderjm6-Nov-12 9:41
vaderjm6-Nov-12 9:41 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
enhzflep6-Nov-12 13:00
enhzflep6-Nov-12 13:00 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
vaderjm6-Nov-12 13:23
vaderjm6-Nov-12 13:23 
Joketl;dr Pin
DarkTizzy6-Nov-12 5:53
professionalDarkTizzy6-Nov-12 5:53 
GeneralRe: tl;dr Pin
enhzflep6-Nov-12 13:06
enhzflep6-Nov-12 13:06 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
Idaho Edokpayi6-Nov-12 16:57
Idaho Edokpayi6-Nov-12 16:57 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
enhzflep6-Nov-12 17:24
enhzflep6-Nov-12 17:24 
The issue of an exact (or ballpark) figure for the sum paid is not something I have examined or considered. It's the willingness to approach and offer to pay something that I'm looking for..

Not quite sure what of my words has led you to conclude that I assume Microsoft to be either/both dissinterested/actively ignoring known vulnerabilities.

In fact, I read just yesterday a request by one of their staff that adequate time to enact a fix be allowed between revealing the vulnerability to them and the general public. (I'll look for a link when I'm done here)
Presumably, they are in the position of asking (rather than dictating) as a direct consequence of failing to enter into a commercial agreement with the holders of said vulnerabilities. My employer pays me, and before doing so has me sign an NDA. Simple.

Paypal have a 'find-the-flaw' system, whereby they OFFER to pay for information related to security flaws in their products. Bad idea, or clever and practical?

I like your analogy - did you approach the lock's maker first, offering you the information you learned to them for a sum, in the interests of them improving their product? Or was this not a consideration, with you instead choosing to go straight to the thieves?

In fact, something somewhat similar happened recently - the maker of electronic door-locks for hotel rooms has had their sloppy work exposed. (I understand that the lock manufacturer was not made aware of this earlier than others. Mad | :mad: Cry | :(( )
Surely this situation is to the benefit of all except those that had formerly been taking advantage of the hack?

http://www.forbes.com/sites/andygreenberg/2012/07/23/hacker-will-expose-potential-security-flaw-in-more-than-four-million-hotel-room-keycard-locks/[^]

Thanks for your thoughts, I appreciate them. Smile | :)
Make it work. Then do it better - Andrei Straut

GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
jschell6-Nov-12 9:04
jschell6-Nov-12 9:04 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
enhzflep6-Nov-12 13:08
enhzflep6-Nov-12 13:08 
AnswerRe: For sale: A new Windows 8 zero-day vulnerability Pin
Casey Sheridan6-Nov-12 10:43
professionalCasey Sheridan6-Nov-12 10:43 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
enhzflep6-Nov-12 12:49
enhzflep6-Nov-12 12:49 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
Casey Sheridan7-Nov-12 1:54
professionalCasey Sheridan7-Nov-12 1:54 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
774655-Nov-12 20:05
774655-Nov-12 20:05 
GeneralRe: For sale: A new Windows 8 zero-day vulnerability Pin
mathomp36-Nov-12 3:20
mathomp36-Nov-12 3:20 
NewsUX: Color is only meaningful if it’s different Pin
Terrence Dorsey1-Nov-12 10:18
sitebuilderTerrence Dorsey1-Nov-12 10:18 
GeneralRe: UX: Color is only meaningful if it’s different Pin
Pete O'Hanlon1-Nov-12 14:18
mvePete O'Hanlon1-Nov-12 14:18 
NewsIssue Tracker: GitHub vs Google Code Pin
Terrence Dorsey1-Nov-12 10:18
sitebuilderTerrence Dorsey1-Nov-12 10:18 
GeneralRe: Issue Tracker: GitHub vs Google Code Pin
Ron Anders1-Nov-12 16:15
Ron Anders1-Nov-12 16:15 
NewsAbstraction: The Rule Of Three Pin
Terrence Dorsey1-Nov-12 10:17
sitebuilderTerrence Dorsey1-Nov-12 10:17 
NewsThe IDE Divide Pin
Terrence Dorsey1-Nov-12 10:17
sitebuilderTerrence Dorsey1-Nov-12 10:17 
NewsTouchDevelop Now Available as Web App Pin
Terrence Dorsey1-Nov-12 10:16
sitebuilderTerrence Dorsey1-Nov-12 10:16 
GeneralRe: TouchDevelop Now Available as Web App Pin
Ravi Bhavnani1-Nov-12 10:43
professionalRavi Bhavnani1-Nov-12 10:43 
GeneralRe: TouchDevelop Now Available as Web App Pin
Terrence Dorsey1-Nov-12 12:25
sitebuilderTerrence Dorsey1-Nov-12 12:25 
NewsApollo Flight Controller 101: Every console explained Pin
Terrence Dorsey1-Nov-12 8:54
sitebuilderTerrence Dorsey1-Nov-12 8:54 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.