最近关于数据库安全有个有趣的问题。Oracle 公司的CSO(chief security officer)写了一篇文章,When security researchers become the problem,首先这位 Davidson 不认为安全研究人员 “push vendors to work faster” 是个好事情; 更为可笑的是 Davidson 觉得这个安全研究人员其实都是为了谋利益而来的:
Many researchers think that the more vulnerabilities they disclose publicly, the more vendors will hire them as consultants.
这多少有点小人之心度君子之腹了.这篇文章一经发出,在安全届引起了不小的讨论.