Matt Fisher on Security, Computers, and Life

Disclosure: Thoughts on Practices and Policies

This page is going to be a living document, more like a personal wiki than just a journal as I think out loud regarding bug-finders dislosure practicies and corresponding policies within organizations.  I recently learned of a large financial organization who makes a practice of literally not responding to anyone who says they found a vulnerability in their product; to the point where they don’t even find out what the vulnerability is.   I find this practice worrisome; particularly as a user of their products.I find that worrisome, but I wonder how many other organizations have that same policy ?

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Follow

Get every new post delivered to your Inbox.