by Ivan Arce
During the past 3 years, I've been involved in the discovery and research of different types of security vulnerabilities in software that lead to the process of producing meaningful reports, notifying the interested parties (vendors and the public in general) and accompanying those parties throughout the process of generating fixes and deploying them.
Last December Microsoft organized SafeNet2000, an invitation only gathering of 250 experts of the information security area to discuss issues related to privacy and security in our times. I was invited to the summit and participated in the Vulnerability Reporting track. Several well known computer security experts from a wide range of interested parties-vendors, consulting firms, government and military, and end customers--tried to agree on a set of guiding principles for the report of security vulnerabilities.
Complete Article >> http://tisc.corecom.com/newsletters/33.html











