ReadWriteHack

Hacker Poll: Should Google Have Disclosed the the Latest Internet Explorer Flaw Before Microsoft Had a Patch?

Google employee Michael Zalewski disclosed a CSS security issue in Internet Explorer today before Microsoft had issued a fix. This is the second time a Google employee has disclosed an IE security flaw to the public before a patch had been issued. Chris Evans posted a cross-site scripting issue to Seclists in September, according to Ars Technica.

The new flaw may also have been reported by two Chinese researchers at a security conference in South Korea according to KrebsonSecurity. Microsoft does not know of any exploits in the wild actually taking advantage of this vulnerability.

Should Google have disclosed these bugs to the public, or waited for Microsoft to issue a fix first?


ReadWriteWeb encourages comments, but please remember: Keep it nice, keep it clean, and avoid promotional comments. We do pre-moderate some comments with links. For more information, please read our full comment policy.
blog comments powered by Disqus
Recommended Story
RWW SPONSORS



RWW PARTNERS