also @ TechSpot: Weekend Open Forum: Most memorable videogame boss fights

Michael Lynn dispute reaches resolution

By

On July 29, 2005, 7:06 AM EST

The story of Michael Lynn, a security researcher at Internet Security Systems (ISS), who gave a presentation on a now-patched flaw in the Internetwork Operating System (IOS) software used to power Cisco's routers, quitting his position at ISS in order to be able to do so, has seemingly been resolved for the moment. Both he and Black Hat (who gave him a venue to give the talk) are off the hook now, thanks to an agreement late yesterday.

Cisco's approach of trying, at all costs seemingly, to silence Lynn on how he reverse-engineered Cisco's software to exploit a known flaw has received unfavourable responses from the security community.

"I am afraid that this controversy will be a setback for security researchers and the full disclosure concept," Fletcher said. "I understand the fact that companies need to have time to patch problems before they are released to the entire world, but it is also important that the world receive this notification within a reasonable time period of the discovery."

"Many of the people working in the trenches to keep our networks secure are very frustrated at the lack of support from their vendors and their employers when it comes to plugging holes like this one," said Stephen Cobb, author of Privacy for Business.

Related Stories

No tags on this story

User Comments (2)

Post a comment
smtkr
on July 29, 2005
11:06 AM
In other words, if your system is insecure, you don't have the right to know about it.

Reply

Phantasm66
on July 29, 2005
12:16 PM
Its not as simple as that. This is a really bad issue, in fact. It means that big corporations are prepared to bully security experts to protect intellectual property rights, reguardless of the eventual effect on the health of the internet. Its bad news.

Reply

Browse more commented news

Post a new comment

Guest user

To post as an anonymous
user click here
.

Members

If you are a TechSpot member,
please login first.


By signing up you gain complete access to the TechSpot community. Join thousands of computer and technology enthusiasts that contribute and share knowledge in our forum. Post messages, get a private inbox, upload your own photo gallery and more.

Subscribe to TechSpot

Get free exclusive content, learn about new features and tech breaking news.