3 ms·
The only official response from Microsoft that I can find is in reply to a question from Bloomberg [1] on this question. Frank Shaw, lead communications for Mic
by gregsq 13y ago
The only official response from Microsoft that I can find is in reply to a question from Bloomberg [1] on this question. Frank Shaw, lead communications for Microsoft, responded by email to the question that, according to Bloomberg, information regarding 0day or other exploits are provided to a number of government agencies as an "early start", prior to public announcement.
The original email text is unavailable as far as I can see. It of course makes perfect sense that, at least under certain circumstances, and this was the sense of limit inferable from the email, that government agencies should be given the opportunity to assess whether the item being notified about has some security implication.
The claim is made by Bloomberg, by reference to "two unnamed government officials", that Microsoft is aware that such information might be applied for reasons not primarily connected to domestic defensive security. But this is only an unsubstantiated assertion.
The number of potential exploits that are known only to Microsoft at the time of notification to those agencies would be, at a lazy guess, somewhat proportional to their exploit assessment man hours, compared to the overall exploit discovery effort. I would think that would be the much smaller proportion.
1. http://mobile.bloomberg.com/news/2013-06-14/u-s-agencies-said-to-swap-data-with-thousands-of-firms.html http://mobile.bloomberg.com/news/2013-06-14/u-s-agencies-sai...