Smart Partner: Bug Fixes Have No Profit Margin | Linux Today

Smart Partner: Bug Fixes Have No Profit Margin

Written By
Web Webster
Web Webster
Oct 26, 2000

“On Oct. 3, the CERT coordination center, a branch of the
Software Engineering Institute at Carnegie Mellon University,
announced that it would begin regularly issuing detailed reports
describing security vulnerabilities in existing software. Under
that new policy, CERT will give software vendors a 45-day “grace
period” after learning of a bug to investigate the problem and
develop patches or workarounds. After 45 days, CERT will release
its report, whether a fix is available or not.”

“The question of vulnerability disclosure is one of the most
hotly debated topics in the network-security community, often
arousing the type of emotional response normally reserved for
abortion or gun control. Many, particularly among open-source
enthusiasts, argue that users and administrators have a right to
information about the software running on their machines. It
follows that security problems should, therefore, be publicized as
widely and in as much detail as possible–including source code
demonstrating how to exploit them. Forewarned is, after all,
forearmed.”

“As one of the few widely trusted and respected players in
the security field, CERT now has the opportunity to become a kind
of central clearinghouse for vulnerability information, while
shaping the standards for responsible disclosure in ways existing
mailing lists cannot.
The end result could make it a lot
easier for the good guys to stay on their toes.”

Complete
Story

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.