Advertisement
Promo

Security threats Toolkit

Court case shines light on security ethics

Dan Ilet ZDNet.co.uk

Published: 13 Jan 2005 13:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The legal action currently being brought by French software company Tegam International against Guillaume Tena, who claimed to have found flaws in its software, has sparked a debate on how the reporting of security vulnerabilities should be handled.

Software companies already face an uphill battle providing good quality patches as fast as possible. But researchers who publish vulnerabilities without informing the software firm beforehand could be making this task harder. This can give hackers a longer lead time to work on an exploit, experts warned on Wednesday

"This is a controversial subject," said Richard Starnes, president of the Information Systems Security Association UK. "The general feeling among the industry is that vulnerability researchers should report problems to the company first and wait a reasonable amount of time before deciding whether to release it or not. The question is how long 'a reasonable amount of time' is."

Patches can be difficult to develop and often take between three and six months to perfect, Starnes said. And there can be backlogs of old vulnerabilities that need to be developed. But this doesn't always sit well with researchers who often like to see immediate results.

"It's about self-gratification for researchers," said Jason Hart, head of security for Whitehat UK. "Companies need to act upon independent researchers' findings. But sometimes researchers give two fingers and say 'your baby's ugly, your software's got holes in it'. No one likes being told their baby is ugly, so they don't take notice. There needs to be a better process."

But while Thomas Kristensen, chief technical officer of Secunia, a Danish company that publishes vulnerabilities, agreed with Starnes and Hart, he also believes that sometimes it is necessary for researchers to disclose vulnerabilities without delay. He said it was better that the public was informed than left ignorant.

"While it's unfortunate when vulnerability details are published without a proper solution from the vendor, it's my opinion that everyone is better off," said Kristensen. "System administrators and private users can reconfigure their systems or discontinue the use of the vulnerable product. Hopefully, this results in the vendor responding in a proper manner in future cases."

At present, no software companies provide financial rewards for those who report valid vulnerabilities to them. But Hart said such a process is needed.

"There are no financial incentives," he said. "If there were incentives, you'd find the software would become very secure overnight. And you'd turn a lot of malicious hackers into good hackers. If there were rewards for vulnerability reporting and they were valid it could work. There just needs to be a proper mechanism in place."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
70 out of 151 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters