Eric Rescorla: VoIPshield’s new policy requiring vendors to pay for full details of bugs in their products. Avaya will no longer make voluntary disclosures of vulnerabilities to Avaya or any other vendor. Instead, the results of the vulnerability research performed by VoIP shield Labs is available to be licensed from VoIPShield for use by Avaya on an annual subscription basis. The new policy is effective immediately, according to a letter from Avaya’s Andy Zmolek of the company.”]

