RE: PivX Advisory MK002A Intuit TurboTax Information Disclosure V ulnerability

From: Jeremy Epstein (jeremy.epsteinat_private)
Date: Thu Mar 13 2003 - 08:51:40 PST

  • Next message: securityat_private: "Security Update: [CSSA-2003-SCO.6] OpenServer 5.0.5 OpenServer 5.0.6 OpenServer 5.0.7 : remote buffer overflow in sendmail (CERT CA-2003-07)"

    Calling these "security advisories" is really misleading.  I keep some of my
    financial calculations in Excel spreadsheets and even in text documents.
    Does that mean you'll be issuing a security advisory on Excel or emacs next?
    And heaven knows, these files are stored in files on disk drives... will you
    be issuing a security advisory that disks present a risk?
    
    I'm having a hard time seeing any value to these "disclosures" other than if
    the goal is to get press attention.  Running P2P sharing is the risk; these
    are examples of why people who choose to use P2P need to be cautious of what
    they share.
    



    This archive was generated by hypermail 2b30 : Thu Mar 13 2003 - 10:27:37 PST