[273] in bugtraq
Re: [8lgm]-Advisory-14.UNIX.SCO-prwarn.12-Nov-1994
daemon@ATHENA.MIT.EDU (Gene Spafford)
Wed Nov 30 16:43:56 1994
To: RAS@CACDVAX.CACD.ROCKWELL.COM
Cc: bugtraq@fc.net
In-Reply-To: Message from RAS@CACDVAX.CACD.ROCKWELL.COM of
"Tue, 29 Nov 1994 16:51:38 -0600"
<941129165138.3b817b62@cacdvax.cacd.rockwell.com>
Date: Wed, 30 Nov 1994 10:24:14 -0500
From: spaf@cs.purdue.edu (Gene Spafford)
> Are there any well substantiated facts which show that full disclosure
> harms the situation?
Yes, and several have been posted here and in the newsgroups over the
last year. Several have also been presented at the FIRST
conferences. Ask anyone on a response team, where they deal with
dozens of breakins a week (or a day, in some cases), and they can give
you lots of evidence (assuming their internal policies allow them to
disclose details of cases).
--spaf