
By Michael S. Mimoso
Excerpt:
Panelist Ivan Arce, chief technology officer of Core Security Technologies wasn't quite in Sotirov's corner as to using exploits as tools to teach vendors lessons, but he wasn't fully behind Kaminsky's course of action and attempt to make a patching decision on behalf of DNS administrators.
"There are admins driven by fear or those driven by recommendations from security vendors or experts. I'd like to think there is a third category, which is those admins and people who would like to manage risk in a rational manner and analyze their situations," Arce said. "To those guys, you need to give them tools if you want to help them to make rational decision."
Source: Search Security











