<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in BMC Response To ZDI: It&amp;#8217;s Magically Litigious!</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Sat, 28 Apr 2007 12:28:12 -0000</lastBuildDate><item><title>Re: BMC Response To ZDI: It&amp;#8217;s Magically Litigious!</title><link>http://www.matasano.com/log/804/bmc-response-to-zdi-its-magically-litigious/#comment-2322089</link><description>Robert: we've looked at, well, a number of systems "like this". Virtually all of that work is under NDA. But I agree, you should be concerned about this whole space of products. Check this out, if you haven't already:&lt;br&gt;&lt;br&gt;&lt;a href="http://www.matasano.com/log/agents-talk" rel="nofollow"&gt;http://www.matasano.com/log/agents-talk&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Sat, 28 Apr 2007 12:28:12 -0000</pubDate></item><item><title>Re: BMC Response To ZDI: It&amp;#8217;s Magically Litigious!</title><link>http://www.matasano.com/log/804/bmc-response-to-zdi-its-magically-litigious/#comment-2322088</link><description>Crazy person, can I ask how you found our blog?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Sat, 28 Apr 2007 12:26:27 -0000</pubDate></item><item><title>Re: BMC Response To ZDI: It&amp;#8217;s Magically Litigious!</title><link>http://www.matasano.com/log/804/bmc-response-to-zdi-its-magically-litigious/#comment-2322087</link><description>Are you serious? Are we night fighting terrorists all over the world or what? This is just another form of terrorism by “independent security firms” So let me see if I really understand this. Some HACK wishing to make a buck steals software and hacks and reverse engineers it. Then terrorizes and extorts money from that company to find out what the HACKER has discovered? Is this independent security research? Sounds like bribery to me. Do you think that there is a software company on the planet that produces bug free code? Do I have this wrong?  Tell me that “independent security firms” do their research for free?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Douglas Farbs</dc:creator><pubDate>Sat, 28 Apr 2007 09:09:21 -0000</pubDate></item><item><title>Re: BMC Response To ZDI: It&amp;#8217;s Magically Litigious!</title><link>http://www.matasano.com/log/804/bmc-response-to-zdi-its-magically-litigious/#comment-2322086</link><description>As an actual BMC customer I have to say this concerns me greatly. I'd like to think that any vulnerabilities in software my employer has spent a lot of money purchasing would be investigated fully no matter where and how the problem was notified.&lt;br&gt;&lt;br&gt;This will certainly have me thinking about whether or not to go with them in the future.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Robert Moir</dc:creator><pubDate>Sun, 22 Apr 2007 04:46:01 -0000</pubDate></item><item><title>Re: BMC Response To ZDI: It&amp;#8217;s Magically Litigious!</title><link>http://www.matasano.com/log/804/bmc-response-to-zdi-its-magically-litigious/#comment-2322085</link><description>We were indeed very dismayed by BMC's decision not to work cooperatively with us or other members of the security research community. &lt;br&gt;&lt;br&gt;One needs only to look at the hard lessons learned by some of the other vendors on this front, to know that this stance is probably not in the best interest of BMC or their customers. &lt;br&gt;&lt;br&gt;Additionally, it puts the ZDI program in an uncomfortable position- where in the absence of cooperation from the vendor, we can only resort to our published policy for dealing with an uncooperative vendor which states: &lt;br&gt;&lt;a href="http://www.zerodayinitiative.com/legal.html" rel="nofollow"&gt;http://www.zerodayinitiative.com/legal.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;"If a vendor fails to acknowledge 3Com's initial notification within five business days, 3Com will initiate a second formal contact by a direct telephone call to a representative for that vendor. If a vendor fails to respond after an additional five business days following the second notification, 3Com may rely on an intermediary to try to establish contact with the vendor. If 3Com exhausts all reasonable means in order to contact a vendor, then 3Com may issue a public advisory disclosing its findings fifteen business days after the initial contact."&lt;br&gt;&lt;br&gt;Sadly, in many cases it may be likely that a patch is not yet available for the issue and those customers would be put at risk for no reason other than this vendor not being willing to recognize the value of independent security research and those who wish to handle that information responsibly.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Terri Forslof</dc:creator><pubDate>Fri, 20 Apr 2007 19:05:08 -0000</pubDate></item></channel></rss>