-
Website
http://www.matasano.com/log -
Original page
http://www.matasano.com/log/866/vulnerability-reporting-in-a-web-20-world/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Press Controls
3 comments · 2 points
-
ChrisMtso
12 comments · 1 points
-
Eric Monti
11 comments · 1 points
-
StatlerAndWaldorf
12 comments · 3 points
-
Dave G.
7 comments · 1 points
-
-
Popular Threads
Perhaps we need a place where researchers like Dave can submit a posting saying they have informed Vendor X of Vulnerability Y on Date Z with CVSS score of A. Then Vendor X can get this taken off the list by saying they fixed it. If it wasn't really fixed Dave can inform the list and it goes back on. Use web 2.0 to police web 2.0.
-Chris
Their response was along the lines of "oops, yeah, we should totally fix that!". I followed up two months later, never heard back and forgot about it until now. Checked again, and they're still vulnerable.
*sigh*
This is maybe about where software companies were 15 or 20 years ago.
unfortunately, only sans-ssi exists right now, although owasp has this:
http://www.owasp.org/index.php/OWASP_Secure_Sof...
and mark curphey got like $200k to work on a project called "owasp ceritification" a few weeks ago which he claims will replace pci. pci-dss and texas are going to hell in a handbasket as they well should.
i talked about this at chisec last night
Others just like to build things...maintenance (and beefing up security) are sometimes not what they want to do. :\
Not saying that's right, but...damnit... :)
Yay! Free education for everybody...
(Or perhaps in your subtlety, you're going to point them at this entry and ask nicely one more time... if so, where's the hash of your advisory?)
If you don't consider the vulnerability serious enough to not use the application, why should they think it is serious enough to expend resources to fix?
In this situation, I dont think the cost of one customer is going to motivate anyone. Besides, not using products and services everytime there is a security issue that isn't resolved to my satisfaction would basically cause me to stop using computers. :)