RE: [VulnDiscuss] Cybersecurity, Research & Disclosure Conference
Chris Wysopal <[email protected]> Wed, 26 Nov 2003 20:10:38 +0000 (GMT)
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
I attended the Stanford Cybersecurity, Research & Disclosure Conference and I can assure you there was no one there advocating laws against disclosure. There was plenty of discussion of the potential liability that surrounds vendors, system owners and exploit developers. If anything there were complaints against the current law we have, DMCA, is overbroad. -Chris On Wed, 26 Nov 2003 [email protected] wrote: > On Fri, 7 Nov 2003, Larry Pingree wrote: > > > 7. Will a law against disclosure stop the black hats in other > > countries from developing exploits? > > More to the point, *no* law against disclosure is going to > stop a blackhat in *any* country. > > One can tell very simply from a patch (in source code or > binary form) what has been changed and why. This is > precisely what caused all the fuss about the flaws in > OpenSSH going into version 3.4 - one can tell from the fix > what the problem was. > > The best that can be hoped to be achieved is that disclosure > is delayed untill the fixes are ready - to release the fixes > is to alert the blackhats and get systems busted into before > the fixes are applied. > > The best that can be hoped for is stopping of kiddies using > exploits for unpatched flaws. > > The "middle ground" of attackers that pen. testers talk > about so much - the fairly good but non-god-like blackhat > attacker will still break systems like they always did. > > There is no way to legislate disclosure to stop blackhats. > > Legislation is *so* the wrong route to go here. So far a > "gentleman's understanding" has worked quite well - the > community needs to educate about how it works, and shun > those who don't abide. > > > bambam > > -- > Cry 'Socket(),' and let slip the packets of war; > >