3 ms·
Funny you mention this, because I don't see US Government, Department of Defense, or the Natural Security Agency on that list (not that I expected to find them
by Breakthrough 13y ago
Funny you mention this, because I don't see US Government, Department of Defense, or the Natural Security Agency on that list (not that I expected to find them there in the first place). Also, last I checked, the purpose of MAPP wasn't to allow MAPP-partners the ability "to exploit vulnerabilities in software sold to foreign governments"... And indeed, that would only compound the problem (have a look at the last question on the MAPP Application Request: "Do you sell or create products used to attack or weaken the security posture of networks or applications?").
> If you want to be outraged, check out all the Chinese companies on the list of partners!
Wow, really? :|
I might be outraged if I saw Government of China on that list, but the majority of Chinese companies on that list are large telecommunications companies (like Huawei) or Chinese-based antivirus companies. And even then, Chinese-based companies only make up a fraction of the (unsettlingly large) list.
- throwaway2048 13y agoits important to note, the government of china has a controlling stake in a large number of those companies.
- fragmede 13y agoI feel it's equally important to note, we don't know which companies on that list are a front for the CIA.
- fuzzbang 13y agoThats because there is more than one program providing this sort of information. MAPP is for AV and other security software companies. There is also: CIPP http://www.microsoft.com/security/cipp/ http://www.microsoft.com/security/cipp/ and another one for "Defence" which is all government, military and intelligence agencies (apparently).
- HelpfulBot 13y agoNatural Security Agency ... hah!
- krapp 13y ago... the intelligence branch of the Department of the Interior?
- freyr 13y ago> last I checked, the purpose of MAPP wasn't to allow MAPP-partners the ability "to exploit vulnerabilities in software sold to foreign governments" The phrase you quoted is utterly meaningless, and the article provides absolutely no evidence that the vulnerability notifications are used for that purpose. It's just an anonymous source is saying "with knowledge of unpatched vulnerabilities, the government could exploit that knowledge." Obviously! With knowledge of unpatched vulnerabilities, YOU could exploit that knoweldge. Anybody could. What of it? The quote is garbage.
- peripetylabs 13y agoI think the US government is not on the list because they don't need this program. The NSA finds its exploits directly from the source code, which Microsoft shares with them and many other governments, not second-hand from Microsoft.