Penetration Testing mailing list archives

Re: [PEN-TEST] disclosure and contact information


From: "Cleary, Tom" <tcleary2 () CSC COM AU>
Date: Thu, 8 Mar 2001 12:01:58 +0800

I think this is a damn good idea.

However, when I've heard stuff like this discussed before ( Check the NANOG
archives and a list relating to the creation of an organisation of
"Responsible ISPs" www.risp.org....? ) they've petered out due to antipathy
from the "Big Boys".

It seems that large Corporations from several sectors only want to hear
from Customers relating to SLA issues and that paying someone to get called
out for an issue that may actually benefit the competition, as well as the
"public good" was not a compelling argument.

It appears to be a good analogy for the "open V. closed" source model
discussions:- For Commercial Corporations, there is no concept of benefit
to the Community other than for PR gain. If you're not a Customer, you
don't exist.

Remember: "Goodwill doesn't show up in a spreadsheet"

You heard it here first.

Regards,

tom.


Current thread: