Advertisement
Promo

Security threats Toolkit

Microsoft seeks credit for finding third-party flaws

Elinor Mills CNET News

Published: 08 Aug 2008 08:29 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft announced at the Black Hat security conference in Las Vegas on Thursday that it is formalising its programme of informing third-party software vendors of security problems with products that run on top of Windows.

"We've seen the threat environment change," said Andrew Cushman, director of the Microsoft Security Response Center.

The Microsoft Security Response Center already reports vulnerabilities to other companies, but now it is asking for recognition in finding the vulnerability. Microsoft will not post advisories on any of the third-party security issues it finds, as it does with vulnerabilities found in its own software, Cushman said.

Read this

Feature
Protect your mobile devices in any location

Forget the recent hype about about Chinese hackers — users and organisations should be securing mobile systems as a matter of course, so follow these tips to find out how

Read more +

The issue of responsible disclosure is under constant debate, with vendors often arguing that researchers are too quick to go public when they find a vulnerability, and researchers countering that, if they didn't go public, the vendors would drag their heels on fixing the problem.

"Microsoft is in a unique position to help in that dimension," he said. "We bring a little different gravitas to the table. I think we can actually change the dynamic around responsible disclosure."

Earlier in the week, Microsoft said it would be giving third-party vendors an advance look at the technical details of the vulnerabilities in Microsoft software before the company releases its monthly 'Patch Tuesday' updates. The company also announced it would help companies prioritise the vulnerabilities contained in its updates.

Credit: Microsoft to seek credit for finding vulnerabilities from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters