[Dshield] standards question

Jonathan Rickman jonathan at xcorps.net
Sat Aug 23 15:29:35 GMT 2003

On Saturday 23 August 2003 10:49, DAN MORRILL wrote:

> So my quesiton is, should I notify? Or will I get in trouble for
> notifying, will they get upset, will I be held responsible in any way. Or
> am I doing a community service by notifying?

You are certainly under no obligation to notify anyone of anything, but it 
is the right thing to do. I do my best to notify those who have suffered 
compromises when time permits, but I feel no guilt for failing to notify 
them when I just do not have the time. Will they get upset? Sometimes they 
might not understand what you are trying to tell them. Some will get 
defensive. Others may level accusations against you. Most are grateful. 
There is simply no way of predicting what the response will be. I'll say it 
again though, you have no obligation to notify and you should not feel 
guilty if you decide it's not worth your time, but it is most definitely 
the right thing to do.

Jonathan Rickman
X Corps Security

