The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
Exposing the user to harm
I don't know, maybe this gets deleted. I think it's valuable site feedback. When a security vulnerability is found in software, there is a specific sequence of events every commercial and open source site I've ever work with, or for, follows.
1) Fix it. 2) Post the patch. 3) Inform the users about the availability of the patch. This is done to protect the users. Any other sequence puts the users at great risk of harm because it announces a security vulnerability before a fix is available. It actually alerts the people who might wish to do harm that a vulnerability exists and has not been patched. Further, you don't give out specifics, such as saying it's an HTML injection issue, until after the patch has been made available. Once again, to keep that information from the hands of those that would do harm. The policy here is backwards, and potentially damaging. |
#2
|
|||
|
|||
/me gives a hug to hambil !!!
|
#3
|
|||
|
|||
/me laughs at all of the stuff going on lately
|
#4
|
||||
|
||||
I agree, and it sounds good. Needs to go through with the plan!!
|
#5
|
|||
|
|||
*deezelpope gives hugs to all you guys...cuz she luvs you and cuz she can.
|
#6
|
||||
|
||||
/me needs a hug too
|
#7
|
|||
|
|||
*deezelpope giggles and hugs Dream...and asks, anyone else?
|
#8
|
|||
|
|||
/me wants to know if you want one from me.
/me looks at the clock and realizes its way past my bed time. Night all |
#9
|
|||
|
|||
*deezelpope says, sure, why not, she's a very loving person. Nighty night, Mike.
|
#10
|
||||
|
||||
The problem is though, unlike the developers you talk about, coders here may have a lack of action.
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|