When is it right to go public with security flaws?
Posted on 27 Jul 2010 at 10:53
“It's just a different name for the same thing,” Sophos's senior technology consultant Graham Cluley told PC Pro.
“Some researchers who don't disclose vulnerabilities in co-ordination with the vendor have got their knickers in a twist that they're seen as irresponsible,” Cluley added. “Microsoft is fed up with the fight between the two sides of thought, and so is hoping to avoid any more debate by no longer using the word ‘responsible’ which implies everything else is irresponsible.”
It’s unclear whether Microsoft has more than terminonolgy discussions planned at Black Hat this year, or whether it will also look to find middle ground with a deadline promise.
Full disclosure
While full disclosure doesn't have the best reputation at the moment, it does more than pile pressure on vendors to fix flaws quickly.
F-Secure researcher Sean Sullivan notes that some vulnerabilities can be headed off by sharing the information. For example, when a security scam hits a social-networking site, the attack can spread quickly – but so can warnings against it. “It has its own immune system, in a way,” he noted.
However, it’s hard to ignore the 25,000 PCs infected by the Windows Support flaw between Ormandy publishing his exploit and Microsoft developing a patch.
Bug bounty
One way of encouraging researchers to share their flaw finds with vendors is by paying them. Several antivirus firms pay up to $10,000 for a vulnerability, while Mozilla and Google have increased their top bounties to around $3,000.
War of words
Tavis Ormandy: "Those of us who work hard to keep networks safe are forced to work in isolation without the open collaboration with our peers that we need."Microsoft: "Once vulnerability details are released publicly, the probability of exploitation rises significantly."
Google: "We define being responsible as doing whatever it best takes to make end users safer."
Microsoft, on the other hand, isn't keen on handing out rewards to bug hunters.“We value the researcher ecosystem, and show that in a variety of ways, but we don’t think paying a per-vuln bounty is the best way,” said Jerry Bryant, group manager for security communications, at Microsoft. “Especially when across the researcher community the motivations aren’t always financial.”
Bryant noted that researchers are rewarded by being credited in Microsoft security bulletins, or by being offered contracts to test the fixes for the flaws they find. Microsoft might even bring the best talent in-house with job offers.
What next for disclosure?
Regardless of what Microsoft announces at BlackHat, there will always be disagreement about which is best: full disclosure or responsible disclosure.
“The security world is made up of many individuals - and they don't all agree,” said Cluley. “Some will side with Tavis Ormandy and his buddies at Google, and others are much more sympathetic to Microsoft's approach of co-ordinating with the vendor.”
“All I can say, is that from my experience most antivirus researchers feel very negatively about anyone who releases information that can help hackers exploit vulnerabilities before a patch is available,” he added. “On too many occasions details of a new vulnerability have been irresponsibly – yes, I'm going to use the word – publicised on the internet, giving hackers a blueprint to create malware that has impacted innocent users.”
Author: Nicole Kobie
From around the web
vista registry issues with updates - error 57e
We have had problems with Office updates on Vista SP2 getting repeated error 57e, well documented on the net in that it is something to do with registry update permissions, we resolved this by uninstalling Rapport
By robmar0se on 28 Jul 2010 ![]()
dgfg
Wonderful.
Share a website with you ,
( http://www.clothes6.us/ )
Believe you will love it.
By linlin1452 on 6 Aug 2010 ![]()
For more details about purchasing this feature and/or images for editorial usage, please contact Jasmine Samra on pictures@dennis.co.uk
advertisement
- Mozilla: everyone should learn a little bit of code
- Google mines social network data for semantic search
- Microsoft tweaks multi-monitor support in Windows 8
- Phone sales shrink as consumers await fresh handsets
- Nvidia warns 28nm supply problems continue
- File-fixing tools to improve uptime in Windows 8
- Mozilla: Microsoft blocking rival browsers in Windows RT
- Microsoft developing sound-based gesture control
- Dell working on Ubuntu Ultrabook for developers
- Media Center to be paid-for add-on in Windows 8
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Samsung Galaxy S III review: first look
- Why you have to be left in the dark on OS patches
- Publishing your email address isn't a security disaster
- Why antivirus is fighting a losing battle in your office
- Four year olds used to steal their parents' data
- An acceptable use policy for your kids
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
advertisement

