Quote:
Originally Posted by bobster65
5) PLEASE DO NOT stop informing members of vulnerabilties!
|
I don't know who you think is suggesting this, but as far as I know nobody has. Some of us have suggested a short delay (in my case I suggested 24 hours) between when the author is contacted and the alert is sent out, and that's assuming the knowledge hasn't gone public (been announced by someone in the hack thread, for example).
You have some good suggestions, but adding to the inaccurate and inflammatory rhetoric of some others in this thread is not helpful.
BTW: For what it's worth, I've been a professional programmer for 25+ years and written security procedures for major companies. If any of my advice gets me onto your no-hire list, then I'd consider that a positive thing.