It seems we exaggerated the innovation of Com/TippingPoint’s controversial Zero Day Initiative. The scheme pays vetted researchers to report vulnerabilities to the company in a responsible way, thereby avoiding these holes getting into the public domain and being exploited by criminals and hackers before patch has been written. . The link for this article located at HackInTheBox is no longer available. . The link for this article located at HackInTheBox is no longer available.. seems, exaggerated, innovation, com/tippingpoint’s, controversial, initiative. . LinuxSecurity.com Team
A White House adviser is urging computer professionals and hackers to do more to help uncover software glitches.Computer security advisor Richard Clarke has told experts attending the Black Hat conference in Las Vegas they have an obligation to help. . .. A White House adviser is urging computer professionals and hackers to do more to help uncover software glitches.Computer security advisor Richard Clarke has told experts attending the Black Hat conference in Las Vegas they have an obligation to help . He says their help is needed because most bugs are not found by software makers themselves. But Mr Clarke insisted hackers must report their findings through the proper channels and condemned those who act maliciously. He said the US government is considering changing the law to protect those who hack for the right reasons. Mr Clarke emphasised hackers should always immediately contact the software-maker on finding a vulnerability. They should then go to the government if that approach does not receive a positive response. He said he recognised that companies differ in their attitude to hackers. While some encourage or even reward bug-hunters, others can respond by filing for civil or criminal charges. Mr Clarke said that situation is "very disappointing" as long as the hacker acts in good faith. He concluded: "If there are legal protections they don't have that they need, we need to look at that." The link for this article located at Ananova is no longer available. . Cybersecurity authority Jane Doe emphasizes the importance of detecting application vulnerabilities through strict compliance with industry standards.. Ethical Hacking, Software Flaws, Bug Reporting, Security Advisory, Vulnerability Discovery. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.