Tagged articles

security policy

4 articles · Page 1 of 1
dbaplus Community
dbaplus Community
Sep 12, 2026 · Information Security

Bill Burr's 2003 Password Rules Were Wrong: He Apologized in 2017

The article traces mandatory complex password rules to Bill Burr's 2003 NIST guide based on a 1980s paper, reveals how they create predictable patterns, cites xkcd's entropy comparison, and notes Burr's 2017 regret and NIST's updated guidelines, yet many sites still enforce the outdated rules.

AuthenticationBill BurrNIST
0 likes · 7 min read
Bill Burr's 2003 Password Rules Were Wrong: He Apologized in 2017
Black & White Path
Black & White Path
May 13, 2026 · Information Security

Why the 90‑Day Vulnerability Disclosure Policy Is Effectively Dead

The article argues that AI‑driven discovery, rapid exploit generation, and simultaneous reporting have shattered the four original assumptions of the 90‑day disclosure window, leaving the policy obsolete as patches often lag behind public exploits and industry debates intensify.

AI securityLinux kernelexploit development
0 likes · 15 min read
Why the 90‑Day Vulnerability Disclosure Policy Is Effectively Dead
iQIYI Technical Product Team
iQIYI Technical Product Team
Dec 25, 2020 · Information Security

iQiyi Security Incident Response Center Vulnerability Handling Policy (Version 3.0)

iQiyi Security Incident Response Center Vulnerability Handling Policy version 3.0 outlines scope, principles, reporting process, severity scoring, reward system, user levels, dispute resolution, and prohibitions, emphasizing dedicated handling, point-based rewards, and strict rules for disclosures and malicious activity.

bug bountyinformation securityrisk assessment
0 likes · 13 min read
iQiyi Security Incident Response Center Vulnerability Handling Policy (Version 3.0)