[SC-L] Insecure Software Costs US $180B per Year - Application and Perimeter Security News Analysis - Dark Reading
Blue Boar
BlueBoar at thievco.com
Thu Nov 29 21:07:00 EST 2007
Andy Steingruebl wrote:
> I like contractual approaches to this problem myself. People buying
> large quantities of software (large enterprises, governments) should
> get contracts with vendors that specify money-back for each patch they
> have to apply where the root cause is of a given type. For example, I
> get money back every time the vendor has a vulnerability and patch
> related to a buffer overflow.
That changes the incentive to hide security bugs and not patch them or
to slipstream them.
BB
More information about the SC-L
mailing list