Telling the goodguys: disseminating information on security holes
Cliff Stoll · 2003
The author discusses what should be done by a software vendor when the product has a security flaw. One alternative, which the author discounts, is to hide the problem and hope it will not be discovered. The alternative, favored by the author, is to widely publicize the patch, hoping that 'badguys' will not reverse engineer it to discover the hole. Several variations are proposed, including distributing an encrypted version of the patch and later publicizing the keyword, and distributing the patch as or on a benign virus.>