Re: [VulnDiscuss] Cybersecurity, Research & Disclosure Conference

Dave Aitel <[email protected]> Wed, 26 Nov 2003 15:58:49 -0500
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
Chris Wysopal wrote:

>I attended the Stanford Cybersecurity, Research & Disclosure Conference and
>I can assure you there was no one there advocating laws against disclosure.
>There was plenty of discussion of the potential liability that surrounds
>vendors, system owners and exploit developers.  If anything there were
>complaints against the current law we have, DMCA, is overbroad.
>
>-Chris
>
>  
>

Of course the main goal of the conference from Microsoft's position was 
to get headlines into the press saying things like "Exploit code on 
trial!" Of course, looking at SecurityFocus makes it obvious they 
succeeded. In reality, there is no case for exploit code to ever be on 
trial. Any potential liability is theoretical at best.

>On Wed, 26 Nov 2003 [email protected] wrote:
>
>  
>
>>On Fri, 7 Nov 2003, Larry Pingree wrote:
>>
>>    
>>
>>>7. Will a law against disclosure stop the black hats in other
>>>countries from developing exploits?
>>>      
>>>
>>>some stuff cut by dave<
>>    
>>

>>The best that can be hoped to be achieved is that disclosure
>>is delayed until the fixes are ready - to release the fixes
>>is to alert the blackhats and get systems busted into before
>>the fixes are applied.
>>
>>The best that can be hoped for is stopping of kiddies using
>>exploits for unpatched flaws.
>>
>>The "middle ground" of attackers that pen. testers talk
>>about so much - the fairly good but non-god-like blackhat
>>    
>>

It's just basically insane at this point to be someone patching a 
production server. If you had a high risk vulnerability on your server, 
you got owned. IMO, the term kiddies has really ceased to have 
relevance. There's a vast host of talented hackers who've been trained 
up over the years. These days if you DID hack a machine, your kernel 
root kit is going to have install problems from conflicting with 
everyone else's.  This usually happens months before a fix is even 
contemplated.

>>attacker will still break systems like they always did.
>>
>>There is no way to legislate disclosure to stop blackhats.
>>    
>>


But there are easy ways to legislate disclosure from hurting Microsoft's 
bottom line via bad PR. This is their goal.  OIS and conventions like 
this are part of the means to that goal. In the long run there are only 
two software companies - Open Source, which has no need for security 
bugs to be hidden, and Microsoft, which benefits greatly.

Dave Aitel
Immunity, Inc.