3 ms·
This is somewhat equivalent to WikiLeaks' release strategy: tell the organization that you have evidence of XYZ problem, but don't describe the exact nature and
by tkiley 17y ago
This is somewhat equivalent to WikiLeaks' release strategy: tell the organization that you have evidence of XYZ problem, but don't describe the exact nature and scope of the evidence, then pressure them to come clean and fix the problem themselves; hopefully this leads to more comprehensive "cleanup" efforts that have a larger positive long-term effect.
How relevant is the WikiLeaks strategy in the field of security?
- tptacek 17y agoIt depends on the vendor. There are vendors for which the "announce and hold back" strategy will probably work: they're the ones who market based on security. It is a Big Deal if someone has an IIS remote, or a reliable Flash, or Apache/WebSphere. We'll see how big a deal it is for Google and Apple. Marketing based on security means more than just talking about security on your web page. It means making a business out of people who buy based on product security. I like my Mac, and I like Apple, but I have no illusions about the resilience of OS X.