Re: [VulnDiscuss] Cybersecurity, Research & Disclosure Conference

Geek Guy <[email protected]> Fri, 28 Nov 2003 07:44:46 -0800
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
    Chris, I am intrigued by the email that you sent, because just 
recenly, your CTO was fired for being a critict of the Microsoft empire. 
It's my opinion that @stake has lost alot of its respect in the industry 
because of this act, and credibility has been lost. I read the paper 
that Dan Geer had released. I completely understand that it was horribly 
slanted towards open systems and some of it poor taste, but was it 
really neccessary to fire him? Anyhow, I've lost alot of respect for 
what I thought was a visionary company.

    As everyone knows, Microsoft is here to stay, but to fire someone 
for only stating the facts is a poor choice.  It is well known that if 
the internet was primarily based on any system, then it would present a 
significant risk of cascading worms, hacks, etc, even if it was based 
primarily on linux. I guess in this world, freedom of speech and the 
speaking of the truth is only based on whom you do business most, it 
makes liars of people representing security and the future of secure 
systems and the stabiliy of the internet.

    Being that I've used, and will continue to use Microsoft products, 
I'm still disapointed that a supposed "Research and Development" company 
cannot release the truth and responds by censoring its real visionaries.

    I agree with Dave, this has allowed Microsoft's marketing machine to 
dictate to the world that their systems are secure, and that they are 
doing something about it, while they continue to release bug fixes for 
sloppy code.


Dave Aitel wrote:

> Chris Wysopal wrote:
>
>> I attended the Stanford Cybersecurity, Research & Disclosure 
>> Conference and
>> I can assure you there was no one there advocating laws against 
>> disclosure.
>> There was plenty of discussion of the potential liability that surrounds
>> vendors, system owners and exploit developers.  If anything there were
>> complaints against the current law we have, DMCA, is overbroad.
>>
>> -Chris
>>
>>  
>>
>
> Of course the main goal of the conference from Microsoft's position 
> was to get headlines into the press saying things like "Exploit code 
> on trial!" Of course, looking at SecurityFocus makes it obvious they 
> succeeded. In reality, there is no case for exploit code to ever be on 
> trial. Any potential liability is theoretical at best.
>
>> On Wed, 26 Nov 2003 [email protected] wrote:
>>
>>  
>>
>>> On Fri, 7 Nov 2003, Larry Pingree wrote:
>>>
>>>   
>>>
>>>> 7. Will a law against disclosure stop the black hats in other
>>>> countries from developing exploits?
>>>>     
>>>> some stuff cut by dave<
>>>
>>>   
>>
>
>>> The best that can be hoped to be achieved is that disclosure
>>> is delayed until the fixes are ready - to release the fixes
>>> is to alert the blackhats and get systems busted into before
>>> the fixes are applied.
>>>
>>> The best that can be hoped for is stopping of kiddies using
>>> exploits for unpatched flaws.
>>>
>>> The "middle ground" of attackers that pen. testers talk
>>> about so much - the fairly good but non-god-like blackhat
>>>   
>>
>
> It's just basically insane at this point to be someone patching a 
> production server. If you had a high risk vulnerability on your 
> server, you got owned. IMO, the term kiddies has really ceased to have 
> relevance. There's a vast host of talented hackers who've been trained 
> up over the years. These days if you DID hack a machine, your kernel 
> root kit is going to have install problems from conflicting with 
> everyone else's.  This usually happens months before a fix is even 
> contemplated.
>
>>> attacker will still break systems like they always did.
>>>
>>> There is no way to legislate disclosure to stop blackhats.
>>>   
>>
>
>
> But there are easy ways to legislate disclosure from hurting 
> Microsoft's bottom line via bad PR. This is their goal.  OIS and 
> conventions like this are part of the means to that goal. In the long 
> run there are only two software companies - Open Source, which has no 
> need for security bugs to be hidden, and Microsoft, which benefits 
> greatly.
>
> Dave Aitel
> Immunity, Inc.
>
>