ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Bug-hunters say firms ignoring security holes

Will Knight ZDNet.co.uk

Published: 18 Oct 2000 09:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Major software firms may be neglecting security vulnerabilities and putting their users at serious risk, according to bug-hunters at Swedish security firm Defcom. The group says the situation has forced it to consider publicising the details of several exploits which would cause the companies involved severe embarrassment.

Although Defcom says the majority of firms respond quickly to alerts, it claims that at least two large firms have failed to get back to it over a number of months. It is now holding last minute discussions with the firms, but says it is still considering releasing details.

"We have found vulnerabilities in major operating systems," says Thomas Olofsson, chief technical officer with Defcom. "More than one company hasn't responded with anything."

Although bugs in operating systems are not uncommon as security mailing lists like Bugtraq illustrate, they are not usually made public until a company has developed a defence against them.

Olofsson is unwilling at this point to disclose information on the bugs, other than to say they pose a risk to users. "These problems are major bugs that could have a serious effect on a lot of people. It is quite irresponsible."

So what can be done to speed the process up? Paul Ashton senior security architect with US security firm Bindview says its just a matter of PR. "There are two things that determine how long it takes for bugs to get fixed and no company feels an obligation to reduce the risk to customers. It depends on bureaucracy and bad public relations." Ashton argues that while internal bureaucracy will slow down the process, concerns over a bad image will speed it up.

David Litchfield, a well-known bug-hunter with security company @Stake says that while things could be improved many companies do respond to alerts quickly. He agrees, however, that it can be a difficult process to go through because of the sheer volume of reports companies receive. He adds that it is important not to jump the gun, when revealing bugs. "The whole point of advisories is to help customers."

These warnings follow a significant change of stance by US government's Computer Emergency Response Team (CERT). The CERT Co-ordination Centre has changed its policy to give companies just 45 days to fix security vulnerabilities before revealing the problem openly. The shift in policy reflects a fundamental movement within the computer security industry towards a more open attitude toward security issues.

To have your say online click on the TalkBack button and go to the ZDNet News forum.

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
54 out of 117 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Senior Java Dev/ Architect - Credit Risk - 600+

Role for a senior Java developer to join the Credit Risk IT team within a top tier Investment Bank. Credit Risk IT is in the very early stages of a ...

Application Support Team Lead - Support Analyst - East Midlands

Carries out full impact analysis of new software releases and recommends upgrade plans liaising with the Enterprise Architect, and Change and ...

Information Security Consultant

You will also conduct security risk assessments and contribute to the development of standards that comply with security policy and best practice. As ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment