[sldev] Viewer security vulnerability disclosure group

Gordon Wendt GordonWendt at gmail.com
Sat Dec 27 07:55:57 PST 2008


Tateru, I think awareness in SL would be higher if LL wanted someone to know
about an issue because they have the unique ability to notify most users
(some viewers don't display that info) when the viewer loads, every user
when they login and every logged in user at will.  That can be done
pre-patch to make people aware of mitigating factors.  They also could
pre-patch enforce that you had to take mitigating steps for example the
quicktime patch where they enforced that you had to upgrade quicktime or
turn quicktime off.  They did this post patch but there's no reason the
mitigation part of it couldn't be done pre patch I don't think, at least on
viewers that weren't coded to ignore this check in which case it's caveat
emptor anyway.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.secondlife.com/pipermail/sldev/attachments/20081227/914e3586/attachment.htm


More information about the SLDev mailing list