Within the context of the latest Windows 10 vulnerabilities ... my boss wants me to send to our entire user base an e-mail concerning this issue, and our actions taken, to reassure everybody. I recommended against it. My reasoning is:
- I've never seen such a thing done before.
- We should not advertise our vulnerabilities, disclose what systems we use or don't use, etc. any more widely than necessary.
- Because patching takes time, we could be inviting abuse of said vulnerability until patching is complete.
- Sometimes patches don't work as intended, and then you just told the world you have a vulnerability, that is now not fixed and still exploitable. Or another vulnerability was introduced, and now everyone knows it exists.
Quick googling could not produce some sort of best practice around these sorts of communications. Although "security through obscurity" isn't valid on its own, some obscurity certainly helps IMO. I get wanting to be transparent and communicative with the user base, but in this case I don't think it's a good idea. Communicating with the relevant executives CIO, etc. should suffice.
What say you?
Thanks.
[link] [comments]
SOCIAL SHARE CARD GENERATOR