Advertisement
Promo

Industry watch Toolkit

Group looks to rein in security experts

Published: 27 Sep 2002 08:22 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Eleven software makers and security firms announced on Thursday the formation of a group that intends to set down rules regarding how the security community should responsibly release information on software flaws.

The members of the group, which first discussed the issues nearly a year ago, hope to bridge the gap between security firms and independent consultants who release information about flaws to grab media attention and the software companies that frequently find themselves with egg on their face over the holes in their applications.

"Today, there are no agreed-upon processes for handling security vulnerabilities," the group said in a statement on its Web site. "The lack of any consensus procedures complicates the process of fixing vulnerabilities, and ultimately increases the risk that all computer users face."

The group stressed that any guidelines that it creates will be just that; no enforcement mechanism will be advocated.

Earlier this year, members of the nascent group supported an official set of draft disclosure guidelines that were submitted to the Internet's technical body, the Internet Engineering Task Force, only to be turned down as being outside the IETF's purview.

The draft guidelines were intended to make peace between the two sides of the security debate: the software companies that want to quietly fix their flawed applications without suffering embarrassment and the security researcher who would rather trumpet the slipups for their own aggrandisement.

The proposed rules suggested that companies respond to security researchers within a week of being notified of a potential flaw and that researchers give software companies at least 30 days to fix the flaw before making information about it public.

That it took a year to organise the group speaks to the difficulty in getting the two sides of the vulnerability equation to see eye to eye.

An incident in June caused a great deal of tension as well. Security firm Internet Security Systems, a member of the OIS, released information about a flaw in the most popular Web server on the Internet, Apache, after only giving a few hours notice to the software's developer group. While the OIS's own guidelines calls for a 30-day period, ISS claimed that the vulnerability was already being used by hackers in the underground and thus needed to be released.

Even so, employees of the group's other members criticised the premature disclosure.

Causing further trouble, according to an employee of another group member who asked not to be identified, is the group's 20-page legal membership agreement.

However, despite the issues, the focus on responsible vulnerability handling in the Bush administration's National Strategy to Secure Cyberspace can only help an initiative such as the OIS.

Members of the group are security companies @Stake, BindView, Foundstone, Guardent, ISS, NAI, and Symantec as well as software makers Caldera International, Microsoft, Oracle and SGI.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
38 out of 83 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Discussions

roger andre roger andre

Context is Everything

Wednesday 9 December 2009, 11:32 PM

2 comments
Moley Moley

Chrome Beta for Linux

Wednesday 9 December 2009, 1:48 PM

1 comment
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters