Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Disclosure Survey
Federico Biancuzzi, 2006-09-05

Federico Biancuzzi surveys statements from some of the world's largest software companies about vulnerability disclosure, interviews two security companies who pay for vulnerabilities, and then talks with three prominent, independent researchers about their thoughts on choosing a responsible disclosure process. In three parts.

Comments Mode:
Disclosure Survey 2006-09-05
LonerVamp (1 replies)
Re: Disclosure Survey 2006-09-05
Matthew Murphy
Disclosure survey 2006-09-05
Todd Knarr
As noted, timeliness of response by the vendor's an issue. Another one is an (IMHO unwarranted) assumption behind all the vendor disclosure rules: that the fact that the general public doesn't know means that the black-hats don't know either. My suspicion is that the black-hats do know about these 0-day vulnerabilities and have been quietly exploiting them long before the researchers uncover them. If that's the case, then suppressing disclosure to the world does nothing to protect anyone and leaves everyone unwittingly open to being exploited. At least if I know there's a vulnerability in some product I can firewall it off or disconnect it or switch products even if there's no fix available. I can't do that if nobody tells me about the problem.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/415/33899#33899







 

Privacy Statement
Copyright 2009, SecurityFocus