[Dataloss] followup: CO University of Colorado at Boulder

security curmudgeon jericho at attrition.org
Fri May 25 18:07:05 UTC 2007


: Ouch - an unpatched bug in so-called SECURITY software? Isn't such 
: software supposed to work against issues that lead to data breaches?

The state of security software is just as dismal as any other product 
line from other vendors though. Search your favorite vulnerability 
database (VDB) for any of the big security vendor names like CA, Symantec 
or Cisco. The results should be an eye opener to anyone who continues to 
use these products.

It's obviously unfortunate, most people are better off having them, as 
they do provide a significant level of protection from various threats. 
But when they are used as attack vectors, the vendors should be ashamed. 
Customers need to hold them to higher standards.



More information about the Dataloss mailing list