[Dataloss] followup: CO University of Colorado at Boulder
security curmudgeon
jericho at attrition.org
Fri May 25 18:07:05 UTC 2007
: Ouch - an unpatched bug in so-called SECURITY software? Isn't such
: software supposed to work against issues that lead to data breaches?
The state of security software is just as dismal as any other product
line from other vendors though. Search your favorite vulnerability
database (VDB) for any of the big security vendor names like CA, Symantec
or Cisco. The results should be an eye opener to anyone who continues to
use these products.
It's obviously unfortunate, most people are better off having them, as
they do provide a significant level of protection from various threats.
But when they are used as attack vectors, the vendors should be ashamed.
Customers need to hold them to higher standards.
More information about the Dataloss
mailing list