Home > Security Tips > Guest Commentary > Use 2004 to strike a blow for responsible disclosure
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

GUEST COMMENTARY

Use 2004 to strike a blow for responsible disclosure


Scott Blake, Guest Contributor
12.19.2003
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Security and IT managers should use the New Year to make a difference in the way vulnerability information is made available to the bad guys.

A set of guidelines for vulnerability reporting released by the Organization for Internet Safety (OIS) recommends a 30-day grace period be observed between when a patch becomes available and technical details of the vulnerability are released. By understanding the policies that vendors and security researchers use to disclose vulnerability information, managers can make decisions about whom to do business with based on whether they follow this advice.

If customers insist that software vendors follow the guidelines and refuse to employ researchers who persist in releasing full technical details of vulnerabilities before fixes are available, we can start to turn the tide.

It used to be that when someone found a security flaw in a piece of software, reports to the vendor requesting a fix were often greeted with threats of lawsuits. Happily, those days are largely behind us, due in large part to the public release of vulnerability information. Pressure from the vendors' customers, and wariness of bad public relations, has driven software companies to take the security of their software seriously -- not to mention the desire to use good security as a competitive differentiator.

These days, software vendors that intentionally ignore vulnerability reports or threaten backlash to researchers are few and far between -- though it does still happen. Full disclosure of vulnerability information succeeded in demonstrating that security flaws in software couldn't be ignored. Unfortunately, wide dissemination of the technical details of using vulnerabilities has also succeeded in making their widespread exploitation nearly trivial. Code that demonstrates vulnerability is typically very easy to transform into a tool a malicious person can use to break into systems.

It's no longer necessary, in most cases, to wield the club of full, immediate disclosure to motivate software vendors to fix flaws in their software. Rather, we suggest that delaying the full disclosure of technical detail doesn't hurt the interests of those with legitimate need for the information, but denies aid to those who seek merely to exploit the problem.

For example, scientific research on software engineering that seeks to analyze large bodies of vulnerability information over time must have full technical information about vulnerabilities, but has no need for that information in the first thirty days it's available. Similarly, a system cracker looking for new ways to break into systems seeks to have information about vulnerabilities that no one else has, or at least that others haven't had a chance to react to. For the system cracker, so-called zero-day (pre-disclosure) vulnerability information is the best, but few have an opportunity to install the patch on the first day it's released, so many systems could still be broken into in the first few days. Technical details about the vulnerability help system crackers develop exploits more quickly.

In 2004, the security community has an opportunity to try a different approach. The OIS guidelines are a starting point for changing the way we think about the requirements of disclosing vulnerability information.

About the author
Scott Blake, CISM, CISSP, is VP of information security at BindView. Opinions expressed in this article are those of the Organization for Internet Safety.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Guest Commentary,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Guest Commentary
Google hacking exposes a world of security flaws
Eliminating the threat of spam email attacks
Outsourcing IT services: Is it worth the security risk?
How permanent is your storage solution?
Honeypots can strengthen reconnaissance and lower intrusion noise
Freedom of speech or lack of professional responsibility?
This year compliance, next year control
Senior security member explains his position on Abagnale
Computer Security Institute's leader responds to Abagnale flap
Spokesman or poster child?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts