Googler criticized for disclosing Windows-related flaw

Googler criticized for disclosing Windows-related flaw
Microsoft and outside security researchers accused a Google engineer of failing to follow the responsible disclosure etiquette his own company promotes by disclosing a Windows XP-related flaw on Thursday, publishing code to exploit it and giving Microsoft only five days to fix it.Tavis Ormandy informed Microsoft about the vulnerability–located in the online Windows Help and Support Center feature that offers customers technical support–on Saturday. He then announced details of the hole and offered proof-of-concept attack code in a post to the Full Disclosure security e-mail list on Thursda

http://news.cnet.com/8301-27080_3-20007421-245.html

Gordon “Fyodor” Lyon, a network security expert and a former president of Computer Professionals for Social Responsibility, praised Ormandy’s research but did not address whether his releasing the exploit was a good thing or not.

With thanks to our major sponsor!

This Spunje is brought to you in association with CloudIntegrations Ltd (www.cloudintegrations.com). The sponsorship agreement allows us to supply this Spunje for free to the readers and remain completely impartial. CloudIntegrations Ltd have no control over the content that is published. We would like to extend our thanks to CloudIntegrations Ltd for their continued financial support.