Home > Information Security Magazine > Columns > Ping
EMAIL THIS LICENSING & REPRINTS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Ping
by Michael S. Mimoso
Issue: Oct 2005
printer-friendly
licensing & reprints

Ciscogate
Ciscogate, the high-profile security standoff between former ISS researcher Mike Lynn and Cisco over the disclosure of a flaw in the IOS router operating system, stirred heavy emotions around responsible vulnerability disclosure and whether there is security in obscurity. Attorney Jennifer Granick, who represented Lynn, is an advocate of responsible disclosure. She provides perspective on this case and what issues it may raise for the future of cyberlaw.

What has this case done for full disclosure advocates? It's gotten people talking about it. Most in the security community feel the amount of information Mike disclosed was completely responsible. In fact, some would say it was not full disclosure--it would have been if he had released exploit code.

Cisco charged that Lynn crossed the line and provided too much information, including trade secrets. What does the law say about trade secrets in this regard? There were no trade secrets at stake here. Mike didn't have the source code, he had the binaries--the product Cisco distributes. Trade-secret laws are about protecting people in a fiduciary relationship of trust from disclosing private information that is economically valuable. The idea is if an insider gets information, they must keep it secret.

As an advocate of full disclosure, what do you believe is a proper means of disclosing information? It really depends; it really is in the eye of the beholder. There are a number of factors that must be considered: Are there patches available? How long have they been out? What kind of information are you disclosing? Is there proof-of-concept code? Are you describing the problem in plain English? The point is, in a computer context, there's no security through secrecy about flaws. If one person has found it, chances are others have as well.

What issues has Ciscogate raised for the future? It will be interesting to see if EULAs deprive someone of the right to reverse engineer a patch. The case will call into question what is a legitimate trade secret. What amount of disclosure is responsible and the audience to which disclosures are made will be a real issue; whether it helps good guys or bad guys. This is the tip of the iceberg.





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts