ISS X-Force Security Advisories on Checkpoint Firewall-1 and VPN-1

Rubens Kuhl Jr. rubens at email.com
Thu Feb 5 20:07:20 UTC 2004


My point is that is very unlikely that both bugs had been discovered by ISS
within the same time frame. Two days is also little time do develop and
test, which raises the suspicion on this issue.

I'm not against notification before disclosure, but it seems that the dates
on this announcement might have been changed in order to make the solution
appear to be developed in very little time. ("See ma, I'm damn fast")


Rubens

> Why is that bad?  I have no objection to giving vendors a reasonable
> amount of time to fix problems before announcing the whole.  Or is your
> point that two days hardly seems like enough time to develop -- and
> *test* -- a fix?
>
> --Steve Bellovin, http://www.research.att.com/~smb




More information about the NANOG mailing list