<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Full Disclosure?</title>
	<atom:link href="http://www.gnucitizen.org/blog/full-disclosure/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/full-disclosure/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Mon, 08 Sep 2008 05:13:09 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: david.kierznowski</title>
		<link>http://www.gnucitizen.org/blog/full-disclosure/#comment-38884</link>
		<dc:creator>david.kierznowski</dc:creator>
		<pubDate>Sat, 04 Aug 2007 13:33:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/full-disclosure#comment-38884</guid>
		<description>Nokia, what you saying is why Full Disclosure came about in the first place really. Researchers got tired of companies pushing their findings aside. In a large way, FD has really helped push the information security industry forward.</description>
		<content:encoded><![CDATA[<p>Nokia, what you saying is why Full Disclosure came about in the first place really. Researchers got tired of companies pushing their findings aside. In a large way, FD has really helped push the information security industry forward.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nokia</title>
		<link>http://www.gnucitizen.org/blog/full-disclosure/#comment-38735</link>
		<dc:creator>Nokia</dc:creator>
		<pubDate>Fri, 03 Aug 2007 18:04:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/full-disclosure#comment-38735</guid>
		<description>Do you alter your thoughts on this dependant on the company/organisation/domain in question?

I recently strongly hinted to a well known organisation about a flaw they had with one of their pages; I didn't receive so much as a thank you in reply - however the flaw was patched in less that 3 hours, which was quite impressive.

The company employs people for this very reason and probably pays them a pretty decent wage....I now take the stance [for this company] that if the folks they are paying can not secure their own set-up and if they are no going to at least appear grateful when someone tells them for fee, then I won't inform them about anything I may discover on their domain in the future - I won't inform anyone else but I certainly won't inform them.</description>
		<content:encoded><![CDATA[<p>Do you alter your thoughts on this dependant on the company/organisation/domain in question?</p>
<p>I recently strongly hinted to a well known organisation about a flaw they had with one of their pages; I didn&#8217;t receive so much as a thank you in reply - however the flaw was patched in less that 3 hours, which was quite impressive.</p>
<p>The company employs people for this very reason and probably pays them a pretty decent wage&#8230;.I now take the stance [for this company] that if the folks they are paying can not secure their own set-up and if they are no going to at least appear grateful when someone tells them for fee, then I won&#8217;t inform them about anything I may discover on their domain in the future - I won&#8217;t inform anyone else but I certainly won&#8217;t inform them.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
