Comments: Towards an Economic Analysis of Disclosure

regarding A, absolutely! That tradeoff, and how to make it was the core of my paper with Crispin Cowan and Steve Beattie on 'Timing the application of security patches for optimal uptime.' One thing we didn't talk a lot about was the cost of applying patches, which we explicitly set to 0. That's wrong, and ignores the reality that there are patches that don't matter enough to apply. But it made modelling easier. :)

Posted by Adam Shostack at January 27, 2005 01:10 PM
Post a comment









Remember personal info?






Hit Preview to see your comment.
MT::App::Comments=HASH(0x55961b73d708) Subroutine MT::Blog::SUPER::site_url redefined at /home/iang/www/fc/cgi-bin/mt/lib/MT/Object.pm line 125.