4 ms·
Kudos to Zed, for at least attempting to find a workable middle-ground. It's a change from the usual and useless finger-pointing.
by itgoon 16y ago
Kudos to Zed, for at least attempting to find a workable middle-ground. It's a change from the usual and useless finger-pointing.
- tptacek 16y agoThe fingerpointing isn't for want of a better system of disclosure. It's because fixing bugs costs money. Very few vulnerability researchers have any notion of how much it costs to roll out a dot release; the idea that it could cost tens of thousands of dollars strikes them as nonsensical. Meanwhile, very few software vendors have any notion of how big a deal (say) memory corruption is; the idea that it cost the public hundreds of thousands of dollars strikes them as nonsensical. All the tools in the world aren't going to get researchers to care about why it's taking 6 months for a vendor to publish their findings. To them, 60 days is an extremely generous window. And all the tools in the world aren't going to educate vendors on the true costs of software vulnerabilities.
- zedshaw 16y agoI mostly disagree with this. Right now the corporations have pretty much stacked the deck against consumers when it comes to security. A simple site where you can go and at least see the amount of vulnerability in a product, and also any past ones could do a lot to change how things are handled currently.
- m0nastic 16y agoHow would this differ from a site like the Zero Day Initiative? (aside from that it looks like there's much less hassle to use this system; or maybe that's actually the point). I think this is interesting, but the two "types of vendors" I see this being useful for are: 1.) Vendors who don't have an already established method for communicating vulnerabilities (and therefore the researcher doesn't have a good way to interact with them). and 2.) Vendors who chose not to work with researchers (of which there used to be a lot, and are still a few). I see type 1 quickly instating a policy to deal with vulnerabilities after something of there's get posted to the site (so they can more quickly deal with future issues), and I see type 2 continuing to ignore vulnerabilities (and possibly being hostile to the researcher and the site for posting things). So maybe the benefit is shaming "type 2" vendors?
- zedshaw 16y agoWhat if this turned into an open source client combined with a standardized API for reporting vulnerabilities directly to vendors and similar escrow services? Ultimately, yes, it's meant to be easier and more open than current initiatives.
- m0nastic 16y agoI think that could be interesting then. One thing that can make it more useful than ZDI is that you lower the barrier of acceptance for a bug. In ZDI, you send them the bug, they decide if they want to buy it from you, and if you accept, they work with the vendor to get it resolved. I can see numerous examples of bugs that they wouldn't necessarily be interested in buying from you, that a system like this could still provide for. I happen to be in the camp who thinks the biggest problem with vulnerability reporting is the lack of response from vendors. A system like this, if it were to become popular, could serve as another way to keep them honest. But in order for it to be ubiquitous, you'd pretty much have to handle dealing with the "biggies", which I think would mean submitting vulnerabilities in the way they advertise. I agree that it shouldn't ideally be up to the vendor how they deal with vulns, but I think you'd have to have tremendous momentum to shift that burden from you to them.
- tptacek 16y agoWhat's the major vendor that won't accept vulnerability reports from researchers? Remember: literally the one and only responsibility a vendor has here is "provide a secure way to send us findings". They don't have to provide a mechanism to post things publicly. If you sit on a finding for 60 days, nobody† will blame a researcher for going public with it. † At least nobody with any influence over your reputation or hirability
- m0nastic 16y agoI don't know about "major" but off the top of my head I can think of a couple hardware vendors who make one-way-transfer appliances who not only won't accept vulnerabilities from researchers, but claim that testing their product for vulnerabilities violates their terms of service, and opens you up to legal action.
- iuguy 16y agohttp://www.secunia.com/ http://www.secunia.com/ does this already. There's heaps of other sites too that do this.