« Using Open Source for Network Security | Main | What a great NAC solution needs, Part 3 »

April 27, 2006

Another IE Zero-day vulnerability possible

Article in e-week yesterday outlined yet another potential critical flaw in Internet Explorer.   It does not seem that  it is for certain whether or not this flaw can actually be exploited though.  One thing I did not like about this, is the researcher who found it, blindsided Microsoft by not first notifying them of the flaw.  This raises an ethical question of whether someone who finds a new vulnerability should have some sort of moral obligation to report the flaw first to the vendor whose product has the flaw, so that they can fix it before the bad guys find out about it.  With many companies like 3Com paying for new vulnerabilities, I think we are not giving much of an incentive for these people who discover these new bugs to do the right thing.  Then on top of this when the media interviews them and treats them to their 15 minutes of fame, the researchers get drunk on the attention. You can't blame these guys for racing to make their findings public under these circumstances.


TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200d8352b30c953ef

Listed below are links to weblogs that reference Another IE Zero-day vulnerability possible:

Comments

My Photo

Subscribe to my blog

Enter your email address:

Delivered by FeedBurner

Lijit Search

Blog Networks

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 2.5 License.

Search

Lijit Search

Attend a Computer Forensics Boot Camp to better your skills and become a better worker
Blog powered by TypePad
Member since 10/2005