Re: [VulnDiscuss] Cybersecurity, Research & Disclosure Conference

Chris Wysopal <[email protected]> Fri, 7 Nov 2003 01:18:25 +0000 (GMT)
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
By my count five out of the seventeen speakers so far work for
organizations involved with the Organization for Internet Safety.
Certainly not a majority, but a lot of participation here shouldn't come as
a surprise as OIS is the only organization that has stepped up and tried to
bring researchers and technology vendors together through a common
disclosure process.

More active independant security researcher participation would help make
the conference better.  I encourage people in this group to either attend
or email Jennifer Granick <[email protected]> about getting a speaker
slot.

-Chris

On Thu, 6 Nov 2003, Cesar wrote:

>
> This seems a "Organization for Internet Safety"
> meeting than a conference. I don't see any active
> independent security researcher in the speaking list.
>
> Cesar.
> --- Chris Wysopal <[email protected]> wrote:
> >
> > Cybersecurity, Research & Disclosure
> > November 22, 2003
> > Stanford Law School
> > http://cyberlaw.stanford.edu/security/
> >
> > Almost daily, newly discovered vulnerabilities are
> > revealed on mailing
> > lists like BugTraq and Full Disclosure.  Harried
> > 'emergency response teams'
> > craft patches and system administrators struggle to
> > implement them
> > system-wide before an attacker can break in.  Is
> > there a better process for
> > discovering flaws and securing computers?  Do
> > privacy and security benefit
> > from the unregulated flow of vulnerability
> > information or should speech be
> > silenced to prevent more attacks?  Will regulation
> > or even criminal
> > penalties promote security, or just help vendors
> > hide the poor quality of
> > their software products from customers?
> >
> > On November 22, Stanford Law School's Center for
> > Internet and Society will
> > host a day-long exploration of the relationship
> > between computer security,
> > privacy, and disclosure of information about
> > security vulnerabilities.
> > Experts from government, industry and academia will
> > gather to debate seven
> > questions addressing how vendors, customers,
> > government, researchers and
> > consumers can better promote vulnerability research,
> > computer security and
> > consumer privacy.
> >
> > Confirmed speakers include:
> >
> > Matt Blaze, AT&T
> > Mary Ann Davidson, Oracle
> > David L. Dill, Professor of Computer Science,
> > Stanford University
> > James Duncan, Cisco
> > Gerhard Eschelbeck, Qualys
> > Stephanie Fohn, Consultant
> > Tiina Havana, Oulu University Secure Programming
> > Group (OUSPG), Finland
> > Shawn Hernan, CERT
> > Steven B. Lipner, Microsoft
> > Simple Nomad, NMRC, Bindview
> > Len Sassaman, Anonymizer
> > Bruce Schneier, Counterpane
> > Peter P. Swire, Professor of Law at Ohio State
> > University
> > Hal Varian, Professor, University of California,
> > Berkeley
> > Vincent Weafer, Symantec
> > Stephen Wu, InfoSec Law Group
> > Chris Wysopal, @stake
> >
> > Anyone who is interested securing the
> > infrastructure, free speech,
> > protecting consumer's privacy and the future of the
> > computer industry
> > should attend this day-long event.
> >
> > Register now at:
> > http://cyberlaw.stanford.edu/security/
> >
>
>
> __________________________________
> Do you Yahoo!?
> Protect your identity with Yahoo! Mail AddressGuard
> http://antispam.yahoo.com/whatsnewfree
>