Re: [VulnDiscuss] Cybersecurity, Research & Disclosure Conference
Dave Aitel <[email protected]> Wed, 26 Nov 2003 15:58:49 -0500
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
Chris Wysopal wrote: >I attended the Stanford Cybersecurity, Research & Disclosure Conference and >I can assure you there was no one there advocating laws against disclosure. >There was plenty of discussion of the potential liability that surrounds >vendors, system owners and exploit developers. If anything there were >complaints against the current law we have, DMCA, is overbroad. > >-Chris > > > Of course the main goal of the conference from Microsoft's position was to get headlines into the press saying things like "Exploit code on trial!" Of course, looking at SecurityFocus makes it obvious they succeeded. In reality, there is no case for exploit code to ever be on trial. Any potential liability is theoretical at best. >On Wed, 26 Nov 2003 [email protected] wrote: > > > >>On Fri, 7 Nov 2003, Larry Pingree wrote: >> >> >> >>>7. Will a law against disclosure stop the black hats in other >>>countries from developing exploits? >>> >>> >>>some stuff cut by dave< >> >> >>The best that can be hoped to be achieved is that disclosure >>is delayed until the fixes are ready - to release the fixes >>is to alert the blackhats and get systems busted into before >>the fixes are applied. >> >>The best that can be hoped for is stopping of kiddies using >>exploits for unpatched flaws. >> >>The "middle ground" of attackers that pen. testers talk >>about so much - the fairly good but non-god-like blackhat >> >> It's just basically insane at this point to be someone patching a production server. If you had a high risk vulnerability on your server, you got owned. IMO, the term kiddies has really ceased to have relevance. There's a vast host of talented hackers who've been trained up over the years. These days if you DID hack a machine, your kernel root kit is going to have install problems from conflicting with everyone else's. This usually happens months before a fix is even contemplated. >>attacker will still break systems like they always did. >> >>There is no way to legislate disclosure to stop blackhats. >> >> But there are easy ways to legislate disclosure from hurting Microsoft's bottom line via bad PR. This is their goal. OIS and conventions like this are part of the means to that goal. In the long run there are only two software companies - Open Source, which has no need for security bugs to be hidden, and Microsoft, which benefits greatly. Dave Aitel Immunity, Inc.