Monday, September 19, 2005

Mary Ann Davidson's view of the relationships between software vendor and the security researchers

Mary Ann Davidson , CSO of Oracle, has recently discussed the differences between perception among security researchers and the reality that the software developers face. Using examples from her company, she addressed three notions that cause conflicts between those groups.
  • You should be able to fix this in two days
  • The more notorious I am, the more business I will get
  • I should always get credit for vulnerabilities I find

To read more on her view, please click here.