Re[2]: [VulnDiscuss] Cybersecurity, Research & Disclosure Conference

Chris Wysopal <[email protected]> Fri, 7 Nov 2003 13:38:40 +0000 (GMT)
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>

On Fri, 7 Nov 2003, Halvar Flake wrote:

> >From what I can see the only relevant researcher on this conference is
> David Litchfield, and due to his experience with SQLSlammer I am not
> sure he is going to be a big counterpoint to the OIS stance. Even if
> he was he'd at least be outnumered 1 to 5.

What does it take these days to be "relevent" or "independant"?  These are
certainly issues to talk about at this conference.  Is just one OIS
participant at a disclosure conference enought to make it an "OIS
conference" and no one should attend given the OIS counterweight? I'm
confident that Stanford will run an open academic conference and all views
will be able to be expressed.

> Perhabs there's so few active independent security researchers because
> they are busy actively researching instead of trying to shape an
> ethical code governing the right way others should go about their
> lives.

Actually the OIS process was shaped by the practices of hundreds of
security researchers and dozens of vendors.  Look at the thousands of
issues disclosed last year and you will find that most follow the spirit of
the OIS process.

> Sometimes it seems there's two disjoint groups in security: Those that
> find relevant bugs, and those in OIS that do not but want to get paid anyhow
> (not 100%ly true, at least ISS has an active and really good research
> team)
>
> The OIS disclosure rules have been drawn up in absence of the research
> community, mainly because the research community can find bugs instead
> of having to argue ethics to justify their existence.

I got involved in OIS because my company discloses many vulnerabilities, 26
so far in 2003. I wouldn't have been invovled in this if we didn't do
active security research and disclose. I can't speak for the others.

> Could someone please step forward and propose a good
> market-for-vulnerabilities model ?

This is actually what I am going to be talking about as part of broader
incentives for vulnerabilitiy researchers.  This conference is not about
squashing research but getting it to flourish.

-Chris


> Cheers,
> Halvar
>
>