Microsoft's manager for security response communication told BetaNews this afternoon that a pledge made by a company representative at a security conference was not, as some sources reported from the scene, a change in policy.
"Microsoft did not announce anything new at ToorCon Seattle regarding its position on responsible disclosure, but we did mention our industry leading online services acknowledgement, which went public in July of 2007," stated Microsoft's Bill Sisk to BetaNews this afternoon. "Because we will not pursue legal action against researchers who report vulnerabilities to us responsibly, we hope to encourage those who want to help us protect customers to feel free to do so without fear of repercussions."
|