ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Security exploits: Who's to blame?

Joris Evers and Marguerite Reardon CNET News.com

Published: 06 Sep 2005 16:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

...a malicious person, may also have found the same flaw and might be using it to attack users, Ferris said.

Often lambasted for bugs in its products, Microsoft is doing its best to win the respect of the security community. The company has "community outreach experts" who travel the world to meet with security researchers, hosts parties at security events and plans to host twice-annual "Blue Hat" events with hackers at its headquarters. At Blue Hat, hackers are invited to Microsoft's headquarters to demonstrate flaws in Microsoft's product security.

"Security researchers provide a valuable service to our customers in helping us to secure our products," said Stephen Toulouse, a program manager in Microsoft's security group. "We want to get face to face with them to talk about their views on security, our views on security, and see how best we can meet to protect customers."

Many companies are getting better at dealing with security researchers, said Michael Sutton, director of iDefense Labs, which deals with researchers and software makers. "The environment has definitely changed from two or three years ago, though there are vendors who are going in the opposite direction," he said.

While Microsoft sometimes is still referred to as the "evil empire", it appears to be successfully wooing security researchers.

"We are at the point where all the obvious things we tell Microsoft to do, they already do it," Dan Kaminsky, a security researcher who participated in Microsoft's first Blue Hat event last March, has said.

Balancing act
Other technology companies still struggle with hacker community relations. Cisco especially has managed to alienate itself from the hacker community to the extent that T-shirts with anti-Cisco slogans were selling well at on of this year's largest international hacking events, the Defcon conference in Las Vegas. Oracle also isn't a favourite, researchers said.

Recently, Cisco sued security researcher Michael Lynn after he gave a presentation on hacking router software at the Black Hat security conference, which was also held in Las Vegas. The company had previously tried to stop Lynn from giving his talk in the first place.

"It was definitely a surprise to see Cisco's reaction," iDefense's Sutton said. "I don't think...

For more, click here...

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
272 out of 513 people found this useful



Company/Topic Alerts

Create a new alert from the list below:












Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

2 comments