|
Full disclosure movement - Definition and Overview |
|
|
|
|
Many hackers believe that posting working code taking advantage of vulnerabilities in a popular program or system will hasten the developers' release of an update or a patch to correct the issue. In some cases, a hacker or cracker may release an easy to use trojan or virus as a proof-of-concept.
It is considered good practice to give developers some time to fix problems and issue patches before full disclosure. This time is usually not very long, and it is rarely extendable. A few days to around a week is considered a good deadline in case of most simple problems (buffer overflows etc.); longer time is given if the problem is particularly deep.
Threat of full disclosure has proven to be a very good guarantee that developers will take care of problems in a timely manner.
See also Hacker, Hacker ethic.
|
|
Example Usage of disclosure |
 |
cheeseandsnark: Universal-Netherworld disclosure-Exposure Administration Division: Cheesemeister and Santa an Item? http://ping.fm/1SpJU |
 |
PussDaddyBlogs: @Etsy I reported this BrookeArin/gemmafactrix non-disclosure issue using your new contact form on your site. |
 |
PussDaddyBlogs: @Etsy following the rules of the site pertaining to disclosure? Is that too much to ask? Thanks. |
|