When Vulnerability Patches Don't Fix the Problem(blog.sourceninja.com)
blog.sourceninja.com
When Vulnerability Patches Don't Fix the Problem
http://blog.sourceninja.com/when-vulnerability-patches-dont-fix-the-problem/
3 comments
I think its just a commercial
We wanted to build a product that helps people get information about the security issues that affect their apps and servers specifically.
Information security has problems getting everyone to know about the security patch when it is pushed. We wanted to address the issue to help everyone be more secure.
Information security has problems getting everyone to know about the security patch when it is pushed. We wanted to address the issue to help everyone be more secure.
How?
I cannot judge the service, I don't use it and never saw it before. But the problem you describe isn't solved by your 'pay to be notified' solution. That samba installation in a small company, done 3 years ago by an intern/student? It won't be fixed. My gut feeling (aka no evidence) says that most installations will be on the small scale, one off. You are offering a service for people who care already - or learned to care.
In other words: It seems to me as if you cater to people that are already on the relevant mailing lists. But maybe you make their life easier..?
I cannot judge the service, I don't use it and never saw it before. But the problem you describe isn't solved by your 'pay to be notified' solution. That samba installation in a small company, done 3 years ago by an intern/student? It won't be fixed. My gut feeling (aka no evidence) says that most installations will be on the small scale, one off. You are offering a service for people who care already - or learned to care.
In other words: It seems to me as if you cater to people that are already on the relevant mailing lists. But maybe you make their life easier..?
We have a free plan also, so everyone can get notified of the issue.
The change won't happen overnight, but if there are tools available that help organizations run more secure software, without false positives, doesn't it benefit everyone?
The change won't happen overnight, but if there are tools available that help organizations run more secure software, without false positives, doesn't it benefit everyone?
Yes. But your tools are just nicer versions of existing ways to care, no?
The AWARENESS problem persists as far as I can tell?
The AWARENESS problem persists as far as I can tell?
They are trying to solve the awareness problem for their customers. They are not trying to solve the awareness problem for the whole world. (Since this is impossible, I do not hold it against them.) You do not have them caught in a contradiction.
I do not want to be 'right' or 'catch' anyone. I try to question and understand.
That said, my parser did find some claim to improve the whole world ('benefit everyone') in the explanation. Nothing bad about that goal either
That said, my parser did find some claim to improve the whole world ('benefit everyone') in the explanation. Nothing bad about that goal either
I need this. As a dev, I want to know whether my dependencies are vulnerable.
Glad to hear.
What do you guys think? Do you think that distribution of patch information is a problem?