This is BrainLog, a blog by Dan Sanderson. Older entries, from October 1999 through September 2010, are preserved for posterity, but are no longer maintained. See the front page and newer entries.

November 15, 2001

Bruce Schneier on bug secrecy vs. full disclosure. When dangerous security holes are found in software, should information about the holes be publicized widely as soon as possible, or should the information be kept quiet so that would-be exploiters of the holes are less likely to be made aware of them while the software vendor works on a fix? Computer security and cryptography mega-guru Schneier summarizes the debate quite nicely.