Verizon's Wade Baker (with assistance from Dave Kennedy, who I will refer interchangeably to as with Wade, Dave or Verizon) published a post claiming that vulnerability/security researchers are given too much leeway, and are closer to criminals than good guys. He suggests they should rather be called "narcissistic vulnerability pimps" (NVPs) in future. Dan Goodin got some clarification when writing his piece for The Register which expands on some of Verizon's motivations and justifications.
While I think I identify with part of his frustrations, he's wrong. Mostly due to an overconfidence in how vendors optimise for "shareholder value", but also because while scrabbling to paint vuln researchers as bad guys, he forgot about the actual bad guys.
Continue reading "In Defence of Vulnerability Researchers"
For the week of 7-14 April
2010, we undertake to talk about this country, its challenges, its
promise, its news, and to ignore Julius while doing so. Join us in this
initiative. If you blog, join the roll. If you Tweet, add the hashtag
#ignoreJulius to your daily output.
However you communicate, take a week off from Julius.
Continue reading "The Ignore Julius Initative"

