Re: [VulnDiscuss] Cybersecurity, Research & Disclosure Conference
Chris Wysopal <[email protected]> Fri, 28 Nov 2003 19:37:53 +0000 (GMT)
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
@stake is fair and factual in all advisories, public statements, and white papers. Look at the work @stake has published as a company and you will see this. If you look at the @stake advisories and even my public statements you will see that @stake has been critical of Microsoft. We have a uniform advisory policy that treats every vendor the same whether they are an @stake customer or not. We do the same in our papers and presentations. I think there is too much bias in the security industry and you even point out that the paper in question was, "horribly slanted towards open systems and some of it poor taste". One way to get beyond bias is to come up with metrics that most people can agree on to compare software for security issues. We need more hard data and less opinions. -Chris On Fri, 28 Nov 2003, Geek Guy wrote: > Chris, I am intrigued by the email that you sent, because just > recenly, your CTO was fired for being a critict of the Microsoft empire. > It's my opinion that @stake has lost alot of its respect in the industry > because of this act, and credibility has been lost. I read the paper > that Dan Geer had released. I completely understand that it was horribly > slanted towards open systems and some of it poor taste, but was it > really neccessary to fire him? Anyhow, I've lost alot of respect for > what I thought was a visionary company. > > As everyone knows, Microsoft is here to stay, but to fire someone > for only stating the facts is a poor choice. It is well known that if > the internet was primarily based on any system, then it would present a > significant risk of cascading worms, hacks, etc, even if it was based > primarily on linux. I guess in this world, freedom of speech and the > speaking of the truth is only based on whom you do business most, it > makes liars of people representing security and the future of secure > systems and the stabiliy of the internet. > > Being that I've used, and will continue to use Microsoft products, > I'm still disapointed that a supposed "Research and Development" company > cannot release the truth and responds by censoring its real visionaries. > > I agree with Dave, this has allowed Microsoft's marketing machine to > dictate to the world that their systems are secure, and that they are > doing something about it, while they continue to release bug fixes for > sloppy code. > > > Dave Aitel wrote: > > > Chris Wysopal wrote: > > > >> I attended the Stanford Cybersecurity, Research & Disclosure > >> Conference and > >> I can assure you there was no one there advocating laws against > >> disclosure. > >> There was plenty of discussion of the potential liability that surrounds > >> vendors, system owners and exploit developers. If anything there were > >> complaints against the current law we have, DMCA, is overbroad. > >> > >> -Chris > >> > >> > >> > > > > Of course the main goal of the conference from Microsoft's position > > was to get headlines into the press saying things like "Exploit code > > on trial!" Of course, looking at SecurityFocus makes it obvious they > > succeeded. In reality, there is no case for exploit code to ever be on > > trial. Any potential liability is theoretical at best. > > > >> On Wed, 26 Nov 2003 [email protected] wrote: > >> > >> > >> > >>> On Fri, 7 Nov 2003, Larry Pingree wrote: > >>> > >>> > >>> > >>>> 7. Will a law against disclosure stop the black hats in other > >>>> countries from developing exploits? > >>>> > >>>> some stuff cut by dave< > >>> > >>> > >> > > > >>> The best that can be hoped to be achieved is that disclosure > >>> is delayed until the fixes are ready - to release the fixes > >>> is to alert the blackhats and get systems busted into before > >>> the fixes are applied. > >>> > >>> The best that can be hoped for is stopping of kiddies using > >>> exploits for unpatched flaws. > >>> > >>> The "middle ground" of attackers that pen. testers talk > >>> about so much - the fairly good but non-god-like blackhat > >>> > >> > > > > It's just basically insane at this point to be someone patching a > > production server. If you had a high risk vulnerability on your > > server, you got owned. IMO, the term kiddies has really ceased to have > > relevance. There's a vast host of talented hackers who've been trained > > up over the years. These days if you DID hack a machine, your kernel > > root kit is going to have install problems from conflicting with > > everyone else's. This usually happens months before a fix is even > > contemplated. > > > >>> attacker will still break systems like they always did. > >>> > >>> There is no way to legislate disclosure to stop blackhats. > >>> > >> > > > > > > But there are easy ways to legislate disclosure from hurting > > Microsoft's bottom line via bad PR. This is their goal. OIS and > > conventions like this are part of the means to that goal. In the long > > run there are only two software companies - Open Source, which has no > > need for security bugs to be hidden, and Microsoft, which benefits > > greatly. > > > > Dave Aitel > > Immunity, Inc. > > > > > >