Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Industry Fears the Red Pill
Richard Forno, 2001-08-30

The security community must choose between the red pill of full disclosure or the blue pill of security through obscurity.

Comments Mode:
Right on! 2001-08-30
Odium Devonix (aka Hatred)
Bad analogy? 2001-09-03
Coldman
Analogy with blue & red pills are a bit strange - in both cases, according to movie, the characters had no chance to find out - what will be _next_, so at some extent it was not really fair.

So, unless you take the pill, you can't find it out, but once you took it - you have no way back.

The same we can see in our world - most products and technologies are offered "as is" - unless you try them you never know - _what_ will happen (if will). But once you took it... Well, for most companies it is not so easy to rollback - I know some which were bought some products, then realized that those are not good enough but they cannot stop using them - money are spent, contracts are signed, etc.

And, this is not easy - to recognize - is specific solution is good or not, unless... You know - you have to try it first, in _real_ world - only _then_ you can decide, and again - unless you are an expert. Most aren't.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/20/6960#6960
Full Disclosure 2001-09-03
H Carvey <keydet89@yahoo.com>
The red pill 2001-09-06
Dave Hudson (1 replies)
The red pill 2001-09-17
abaximus "mailto:pr0digy26@hotmail.com"







 

Privacy Statement
Copyright 2008, SecurityFocus