Re: In reply to comments about new policy

Greg Woods (woods@ncar.ucar.edu)
Tue, 29 Nov 94 11:18:06 MST

I think you need to define what you mean by "full disclosure" here. I'm
all in favor of immediate disclosure of holes and descriptions of how
to exploit them, but I am against including with the first disclosure
actual programs and scripts that make it trivial for any bozo who
hasn't a clue to exploit the holes.  Should I vote "yes" or "no" to
express that opinion?

--Greg (root@ucar.edu)