Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Microsoft Reveals Anti-Disclosure Plan
Kevin Poulsen, SecurityFocus 2001-11-09

Five computer security firms join Microsoft to set an official standard for limiting disclosure of software security holes

Comments Mode:
Microsoft Reveals Anti-Disclosure Plan 2001-11-09
Anonymous (1 replies)
Microsoft Reveals Anti-Disclosure Plan 2001-11-10
Gregarious Monk
What about the admins? 2001-11-09
ferretzero
Microsoft Reveals Anti-Disclosure Plan 2001-11-09
russell handorf
Microsoft Reveals Anti-Disclosure Plan 2001-11-09
Angus Blitter
30 days makes no difference 2001-11-09
Anonymous
Microsoft Reveals Anti-Disclosure Plan 2001-11-09
kishg (at) optonline (dot) com [email concealed]
Shocking developments 2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (2 replies)
Shocking developments 2001-11-09
Anonymous
Shocking developments 2001-11-09
Greggory Peck
Be careful what you wish for. 2001-11-09
Surreal
Such a policy for disclosure already exists 2001-11-09
Dumky (1 replies)
Such a policy for disclosure already exists 2001-11-10
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]>
...on second thought...Kudos! 2001-11-09
H Carvey <keydet89 (at) yahoo (dot) com [email concealed]> (1 replies)
RE: ...on second thought...Kudos! 2001-11-10
Gregarious Monk
RFP (Rain Forest Puppy) 2001-11-10
Anonymous
Microsoft Reveals Anti-Disclosure Plan 2001-11-10
Anonymous


something definitly comes to my mind, most of (not to say all) juicy informations available on the bugtraq and all others interesting sources whatever they are (papers, ezine, exploits etc..) usually come from independant security [club of]? researchers and by any mean from commercial vendors like M$, iss, @stake and the like.

For the latters, blocking full disclosure is a matter of protecting their buisness, a good way and legal way to make even more profit by dropping minded customers into ignorance (a good point for software vendors) and letting them more exposed (perfect for security vendors). This is basically the link between M$ and IT security companies. One make huge holes, others are living upon.

Another interesting point is the limited availability of the information "a la Cert", just enough for security companies to make further researches, this kind of research their customers just can't afford cauz of a lack of time, cash or skills.

What would happen with all these good free stuffs like snort nessus and others.. ?

By the way, i guess that underground may become the main security source for some security officers one day or another if such a proposal become the international and legal way to share such informations, that's an announced nightmare for most of you.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/281/8715#8715
Read the fine print 2001-11-11
Anonymous
Cross your fingers... 2001-11-11
Anonymous
Full disclosure will survive 2001-11-11
Ben - Canberra AUS
So, green light to sue? 2001-11-12
Anonymous
Microsoft have no server monopoly: this may reduce their share 2001-11-12
Kirsten Bayes (kirruth@hushmail)







 

Privacy Statement
Copyright 2009, SecurityFocus