FeedFan - Syndication made easy


Slashdot

Should Vendors Close All Security Holes?


johnmeister writes to tell us that InfoWorld's Roger Grimes is finding it hard to completely discount a reader's argument to only patch minimum or low security bugs when they are publicly discovered. "The reader wrote to say that his company often sits on security bugs until they are publicly announced or until at least one customer complaint is made. Before you start disagreeing with this policy, hear out the rest of his argument. 'Our company spends significantly to root out security issues,' says the reader. 'We train all our programmers in secure coding, and we follow the basic tenets of secure programming design and management. When bugs are reported, we fix them. Any significant security bug that is likely to be high risk or widely used is also immediately fixed. But if we internally find a low- or medium-risk security bug, we often sit on the bug until it is reported publicly. We still research the bug and come up with tentative solutions, but we don't patch the problem.'"

Read more of this story at Slashdot.



View full item



Go to syndication wizard for this feed
Go to the history for this feed
Go to the archive for this feed






 
 
Webhosting by VDX · Copyright © 2007-2010 FeedFan / Feed Folder
Other websites: CitySite · FeedFolder · FinPo · Starten · 1Stop Webshop