Jump to content

RFPolicy

From Niidae Wiki

Template:Short description Template:One source The RFPolicy states a method of contacting vendors about security vulnerabilities found in their products. It was originally written in 2000<ref name="bugtraq">Template:Cite web</ref> by hacker and security consultant Rain Forest Puppy.<ref>Template:Cite web</ref> It was perhaps the second disclosure policy, following Simple Nomad's.<ref name="nmrc">Template:Cite web</ref>

The policy gives the vendor five working days to respond to the reporter of the bug. If the vendor fails to contact the reporter in those five days, the issue is recommended to be disclosed to the general community. The reporter should help the vendor reproduce the bug and work out a fix. The reporter should delay notifying the general community about the bug if the vendor provides feasible reasons for requiring so.

If the vendor fails to respond or shuts down communication with the reporter of the problem in more than five working days, the reporter should disclose the issue to the general community. When issuing an alert or fix, the vendor should give the reporter proper credits about reporting the bug.

Context for the history of vulnerability disclosure is available in a history article.<ref name="duo">Template:Cite web</ref>

References

[edit]

Template:Reflist

[edit]

Template:Comp-sci-stub