ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Don't pay for insecure software, says SANS

Dan Ilet ZDNet.co.uk

Published: 11 Oct 2004 10:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security organisation SANS has slammed the vendor community for failing to provide secure products.

While answering panel questions at the SANS Institute's Top 20 Vulnerabilities conference at the Department of Trade and Industry's offices in London on Friday, director of research for the organisation Alan Paller lashed out at vendors for leaving users to solve patching issues.

"This is not your problem," said Paller, addressing the audience of IT security managers. "You did not cause this. This is the vendors' problem. They get you into this state." Paller called for vendors to do more on testing before they sell their products. He said that IT professionals should hold onto their money until vendors have proved that the product works. "The way you fix it is that you still have the pound your hand," he said. "Make everyone who sells you something run a full security scan and give results before they sell a product, then that makes it their problem."

Oracle also came under fire in Paller's attack: "Oracle is famous for giving out patches that undo all your fixes," he said.

But Oracle hit back at Paller's claims, referring to Microsoft and IBM's security practice.

In an email statement, the company said: "Oracle, of any major software vendor, offers the most widely tested software with several international security evaluations (17 for database, 19 overall) compared to one evaluation for Microsoft's database and none for IBM. When software security flaws are discovered, Oracle responds as quickly as possible with patches and workarounds in order to help protect information secured by customers in Oracle-based information systems."

At the beginning of the conference, Paller referred to Microsoft having won a SANS award last year for its auto-updates service. Chief security advisor for Microsoft UK Stuart Okin said that vendors are already doing as much as they can.

"I think overall that vendors do as much possible," said Okin. "Microsoft being one of the biggest companies absolutely needs to stake the lead in this. SANS awarding Microsoft is an example of how we are trying to teach our developers. And I absolutely agree that vendors need to do this."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
83 out of 175 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Media Sciences Analyst

This may be the target audience, sales objectives, regionality, implications of the marketplace, competitive context, etc. The group has over 200 ...

NHS & Public Sector HR candidates - Contracts in London & South East

I work with clients across London & the South East who are seeking candidates in the following areas: I specialise in providing qualified HR ...

CRM Technical SME

Advisor relationship with our clients and the shaping, design and delivery of medium to large scale, complex, integrated Customer Management Business ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation