Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

IMO there should be some sort of header like

    x-whitehat: autopatch
which gives white-hats the opportunity to patch your system without exploiting. The why I see it, a malicious person is going to exploit your server anyway. This way white-hats could patch your system and not be prosecuted. With this, someone who discovered the patch could scan the internet, look for servers that say "yes, please patch me" and deploy a quick patch and nothing else.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: