Definitely.
I'd agree that some problems are only known after they have been exposed, but who exposes those and how people react are key. Work can (and is) put into hardening security by those who take it seriously. This ranges from the monitoring described right through to more proactive attempts to break a system. It's better for a friend to find a flaw than a foe. I wonder if PlusNet have ever had an impartial external assessment of their policies?



Pages in this thread:
Print Thread
h0tblack