, SecurityFocus 2001-11-09
Five computer security firms join Microsoft to set an official standard for limiting disclosure of software security holes
Expand all |
Post comment
Shocking developments
2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (2 replies)
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (2 replies)
Such a policy for disclosure already exists
2001-11-09
Dumky (1 replies)
Dumky (1 replies)
Such a policy for disclosure already exists
2001-11-10
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]>
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]>
...on second thought...Kudos!
2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (1 replies)
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (1 replies)
So what would force Microsoft to patch these holes if exploits are not published?
2001-11-10
Rafal Sybilla-Leszczynski (1 replies)
Rafal Sybilla-Leszczynski (1 replies)
So what would force Microsoft to patch these holes if exploits are not published?
2001-11-12
Anonymous
Anonymous
Microsoft have no server monopoly: this may reduce their share
2001-11-12
Kirsten Bayes (kirruth@hushmail)
Kirsten Bayes (kirruth@hushmail)

I am definetely a white hat. I am an independant researcher and a computer security professionnal. I have never done anything illegal in terms of intrusion, copyright-stealing or whatever, but with these laws, and the interactions between them, it will become clear that some concepts and ideas will merge. So, 2-3 years from now, we could see a 15 year old who find a big hole on Outlook GZ (fake name of course) and takes the gut to publish it online. Not only he would violate the information disclosure policy put in place by force by Microsoft, but since the exploit permits the attacker to execute code on a (tentatively?) protected machine, this would hit also the DMCA for "circumventing an access device". Since our teenager already face two possibly-criminal charges for something he thought was completely legal (albeit thrilling), it is not hard to imagine how all this can be nicely packaged in a terrorist scheme (ok, let's say the teenager is actually 24 and of non-white ethnicity) and lock him up for a veeeerryy long time behing bars.
This can not go on.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/281/8657#8657