-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/804/bmc-response-to-zdi-its-magically-litigious/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
One needs only to look at the hard lessons learned by some of the other vendors on this front, to know that this stance is probably not in the best interest of BMC or their customers.
Additionally, it puts the ZDI program in an uncomfortable position- where in the absence of cooperation from the vendor, we can only resort to our published policy for dealing with an uncooperative vendor which states:
http://www.zerodayinitiative.com/legal.html
"If a vendor fails to acknowledge 3Com's initial notification within five business days, 3Com will initiate a second formal contact by a direct telephone call to a representative for that vendor. If a vendor fails to respond after an additional five business days following the second notification, 3Com may rely on an intermediary to try to establish contact with the vendor. If 3Com exhausts all reasonable means in order to contact a vendor, then 3Com may issue a public advisory disclosing its findings fifteen business days after the initial contact."
Sadly, in many cases it may be likely that a patch is not yet available for the issue and those customers would be put at risk for no reason other than this vendor not being willing to recognize the value of independent security research and those who wish to handle that information responsibly.
This will certainly have me thinking about whether or not to go with them in the future.
http://www.matasano.com/log/agents-talk