[VulnDiscuss] Cybersecurity, Research & Disclosure Conference

Chris Wysopal <[email protected]> Thu, 6 Nov 2003 22:02:35 +0000 (GMT)
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
Cybersecurity, Research & Disclosure
November 22, 2003
Stanford Law School
http://cyberlaw.stanford.edu/security/

Almost daily, newly discovered vulnerabilities are revealed on mailing
lists like BugTraq and Full Disclosure.  Harried 'emergency response teams'
craft patches and system administrators struggle to implement them
system-wide before an attacker can break in.  Is there a better process for
discovering flaws and securing computers?  Do privacy and security benefit
from the unregulated flow of vulnerability information or should speech be
silenced to prevent more attacks?  Will regulation or even criminal
penalties promote security, or just help vendors hide the poor quality of
their software products from customers?

On November 22, Stanford Law School's Center for Internet and Society will
host a day-long exploration of the relationship between computer security,
privacy, and disclosure of information about security vulnerabilities.
Experts from government, industry and academia will gather to debate seven
questions addressing how vendors, customers, government, researchers and
consumers can better promote vulnerability research, computer security and
consumer privacy.

Confirmed speakers include:

Matt Blaze, AT&T
Mary Ann Davidson, Oracle
David L. Dill, Professor of Computer Science, Stanford University
James Duncan, Cisco
Gerhard Eschelbeck, Qualys
Stephanie Fohn, Consultant
Tiina Havana, Oulu University Secure Programming Group (OUSPG), Finland
Shawn Hernan, CERT
Steven B. Lipner, Microsoft
Simple Nomad, NMRC, Bindview
Len Sassaman, Anonymizer
Bruce Schneier, Counterpane
Peter P. Swire, Professor of Law at Ohio State University
Hal Varian, Professor, University of California, Berkeley
Vincent Weafer, Symantec
Stephen Wu, InfoSec Law Group
Chris Wysopal, @stake

Anyone who is interested securing the infrastructure, free speech,
protecting consumer's privacy and the future of the computer industry
should attend this day-long event.

Register now at: http://cyberlaw.stanford.edu/security/