Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Microsoft Reveals Anti-Disclosure Plan
Kevin Poulsen, SecurityFocus 2001-11-09

Five computer security firms join Microsoft to set an official standard for limiting disclosure of software security holes

Comments Mode:
Microsoft Reveals Anti-Disclosure Plan 2001-11-09
Anonymous (1 replies)
Microsoft Reveals Anti-Disclosure Plan 2001-11-10
Gregarious Monk
What about the admins? 2001-11-09
ferretzero
Microsoft Reveals Anti-Disclosure Plan 2001-11-09
russell handorf
Microsoft Reveals Anti-Disclosure Plan 2001-11-09
Angus Blitter
30 days makes no difference 2001-11-09
Anonymous
Microsoft Reveals Anti-Disclosure Plan 2001-11-09
kishg (at) optonline (dot) com [email concealed]
Shocking developments 2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (2 replies)
Shocking developments 2001-11-09
Anonymous
Shocking developments 2001-11-09
Greggory Peck
Microsoft Reveals Anti-Disclosure Plan 2001-11-09
Tommy Ward
Looks like one step closer to outlawing security research by anyone other than "legitimate" (corporate) entities. So they form a club and require membership dues of $5-10 K / year...this will provide barrier to entry for anyone except large vendors. Then, with standards in place which set these stringent guidelines for disclosure, they can start to brand anyone who does full disclosure as "not complying with standard industry practices." This can open up opportunities for civil action against those who dare to point out the emperor's nakedness. Criminal sanctions aren't far behind this.

One weakness they are exposing which we can all fight has to do with the RFC approach. Everyone who has a concern with the direction this is going should provide comments during the RFC process, and anyone who has time and ability should participate in the working group sessions to change the RFC.

Microsoft has beaten our federal government into submission, also nine states, and 99% of commercial businesses. While they attempt to take over not only the Internet but the information security industry as well, it is in our best interests to fight them with any and all tools available.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/281/8678#8678
Be careful what you wish for. 2001-11-09
Surreal
Such a policy for disclosure already exists 2001-11-09
Dumky (1 replies)
Such a policy for disclosure already exists 2001-11-10
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]>
...on second thought...Kudos! 2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (1 replies)
RE: ...on second thought...Kudos! 2001-11-10
Gregarious Monk
RFP (Rain Forest Puppy) 2001-11-10
Anonymous
Read the fine print 2001-11-11
Anonymous
Cross your fingers... 2001-11-11
Anonymous
Full disclosure will survive 2001-11-11
Ben - Canberra AUS
So, green light to sue? 2001-11-12
Anonymous
Microsoft have no server monopoly: this may reduce their share 2001-11-12
Kirsten Bayes (kirruth@hushmail)







 

Privacy Statement
Copyright 2007, SecurityFocus