vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin.org Site Feedback (https://vborg.vbsupport.ru/forumdisplay.php?f=7)
-   -   Exposing the user to harm (https://vborg.vbsupport.ru/showthread.php?t=151083)

hambil 07-01-2007 04:07 AM

Exposing the user to harm
 
I don't know, maybe this gets deleted. I think it's valuable site feedback. When a security vulnerability is found in software, there is a specific sequence of events every commercial and open source site I've ever work with, or for, follows.

1) Fix it.
2) Post the patch.
3) Inform the users about the availability of the patch.

This is done to protect the users. Any other sequence puts the users at great risk of harm because it announces a security vulnerability before a fix is available. It actually alerts the people who might wish to do harm that a vulnerability exists and has not been patched.

Further, you don't give out specifics, such as saying it's an HTML injection issue, until after the patch has been made available. Once again, to keep that information from the hands of those that would do harm.

The policy here is backwards, and potentially damaging.

nexialys 07-01-2007 04:09 AM

/me gives a hug to hambil !!!

Michael Biddle 07-01-2007 04:15 AM

/me laughs at all of the stuff going on lately

FreshFroot 07-01-2007 04:21 AM

I agree, and it sounds good. Needs to go through with the plan!!

deezelpope 07-01-2007 09:38 AM

*deezelpope gives hugs to all you guys...cuz she luvs you and cuz she can.

Dream 07-01-2007 09:56 AM

/me needs a hug too

deezelpope 07-01-2007 09:59 AM

*deezelpope giggles and hugs Dream...and asks, anyone else?:D

Michael Biddle 07-01-2007 09:59 AM

/me wants to know if you want one from me.

/me looks at the clock and realizes its way past my bed time. Night all

deezelpope 07-01-2007 10:02 AM

*deezelpope says, sure, why not, she's a very loving person.:) Nighty night, Mike.:D

Dismounted 07-01-2007 10:26 AM

The problem is though, unlike the developers you talk about, coders here may have a lack of action.


All times are GMT. The time now is 03:33 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01088 seconds
  • Memory Usage 1,726KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete