I have seen cases where customers find relatively advanced bugs in software. These customers contact the vendor, the vendor acknowledges the bug and provides a fix for it. Now, the question is, should the public BugID refer back to the original customer/company who found this bug? i.e., Should that company get a 'cred' for it?
The reason I ask is because I have seen scenarios where certain customers (usually banks) will find a bug and after its been fixed, they will ask that their information NOT be made public as it relates to that bug. Then we have the flipside where the customer calls in and asks "Hey, so do we get any recognition for finding this bug?".
Soo..
Should it be:
1.) Let the customer decide
2.) Publish information on who originally found the bug
3.) Hide information on who originally found the bug
The reason I ask is because I have seen scenarios where certain customers (usually banks) will find a bug and after its been fixed, they will ask that their information NOT be made public as it relates to that bug. Then we have the flipside where the customer calls in and asks "Hey, so do we get any recognition for finding this bug?".
Soo..
Should it be:
1.) Let the customer decide
2.) Publish information on who originally found the bug
3.) Hide information on who originally found the bug

Posted by 199.172.169.9 on December 22, 2004 at 11:52 AM PST #
Posted by Paul Greidanus on December 22, 2004 at 11:54 AM PST #
Posted by Moazam on December 22, 2004 at 11:55 AM PST #
Posted by K G on December 22, 2004 at 02:57 PM PST #
Posted by Sean Yunt on December 22, 2004 at 05:09 PM PST #
Posted by Moazam on December 22, 2004 at 05:32 PM PST #
Posted by Iain on December 22, 2004 at 09:29 PM PST #