December 21, 2000

Disclosure ethics revisited

Author: JT Smith

"Over the past six months, Marcus Ranum, a
well-respected player in the security field and CTO of
Network Flight Recorder Inc., has become a focal point
in one of the most heated debates in the security
community. In July 2000, Ranum called for a reassessment
of the ethics of security practice, and in so doing,
challenged one of the community's most sacred of cows:
the way in which security vulnerabilities are disclosed to
the public. In November, Mr. Ranum agreed to share his
views on that issue with Sm@rt Partner."


