On mySimon: Logitech MX Revolution Laser Mouse
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Jan 26, 2005 12:00:00 PM

To many software makers and security consultants, flaw finder David Aitel is irresponsible.

The 20-something founder of vulnerability assessment company Immunity hunts down security problems in widely used software products. But unlike an increasing number of researchers, he does not share his findings with the makers of the programs he examines.

Last week, Immunity published an advisory highlighting four security holes in Apple Computer's Mac OS X--vulnerabilities that the security company had known about for seven months but had kept to itself and its customers instead of disclosing the problem to Apple.

News.context

What's new:
Despite pressure from Microsoft and other companies about the dissemination of security alerts, independent researchers are sticking to their own approach to flaw disclosure.

Bottom line:
The debate about when and how to inform people about security risks is causing fractures in the industry.

More stories on this topic

"I don't believe that anyone has an obligation to do quality control for another company," Aitel said. "If you find out some information, we believe you should be able to use that information as you wish."

Despite efforts from Microsoft and other companies to direct how and when security alerts are sent out, independent researchers like Aitel are sticking to their own vision of flaw disclosure.

For them, software companies have become too comfortable in dealing with vulnerabilities--a situation that has resulted in longer times between the discovery of security holes and the release of patches.

At the heart of the issue is the software industry push for "responsible" disclosure, which calls on researchers to delay the announcement of security holes so that manufacturers have time to patch them. That way, people who use flawed products are protected from attack, the argument goes. But the approach also has benefits for software makers, a security expert pointed out.

"As long as the public doesn't know the flaws are there, why spend the money to fix them quickly?" said Bruce Schneier, chief technology officer at Counterpane Internet Security, a network monitoring company. "Only full disclosure keeps the vendors honest."

The debate over how open the discussion of flaws should be is not a new one. The locksmith community has been talking over the issue for more than a century and a half, and it still has failed to find consensus.

Matt Blaze, a computer science professor at the University of Pennsylvania, has seen firsthand the ire that the issue can raise. Blaze has studied how security threats in the logical world compare to problems with physical locks in the real world. His papers have revealed weaknesses in locks that some professional locksmiths would have liked to keep secret.

""We, as professionals in the security field, are outraged and concerned with the damage that the spread of this sensitive information will cause to security and to our profession," a person claiming to be a retired locksmith wrote in a bulletin board posting about Blaze's work.

That reaction is nothing new, Blaze found. Locksmiths have always been close-mouthed about the weaknesses of locks and, as far back as the mid-19th century, an inventor of mechanical locks found it necessary to defend himself when he published details of such flaws.

"Rogues knew a good deal about lock picking long before locksmiths discussed it among themselves, as they have lately done," Alfred C. Hobbs wrote in a book published in 1853, according to Blaze's site. The author also wrote:

"If a lock, let it have been made in whatever country or by whatever maker, is not so inviolable as it has hitherto been deemed to be, surely it is to the interest of honest persons to know this fact, because the dishonest are tolerably certain to apply the knowledge practically; and the spread of the knowledge is necessary to give fair play to those who might suffer by ignorance."

In the past, many hackers and security researchers outed glitches without much thought of the impact on Internet users. Microsoft, among others, changed this. As part of its 3-year-old "Trustworthy Computing" initiative to tame security problems in its software, the company began an outreach program to support the work of the security community. At the same time, it started chastising those researchers who, it believed, released details of flaws too early.

Balance of power?
The result is a tradeoff between security researchers and software businesses that is supposed to benefit product users.

Apple, for example, keeps the work of its security team wrapped in secrecy and issues patches approximately every month. Microsoft has moved to a strict second-Tuesday-of-each-month patch-release schedule, unless a flaw arises that poses a critical threat to customers' systems. Database maker Oracle has settled on a quarterly schedule.

"We think it is in the best interest of our customers," said Kevin Kean, director of Microsoft's security response center. "A large portion of the research community agrees with us and works with us in a responsible way."

But some security researchers believe the tradeoff is benefiting companies too much, as it allows them to tweak their patching processes at their convenience, and without the need to introduce fixes disturbing the progress of software development. That adds up to a lax attitude to security, some experts believe.

For example, eEye Digital Security abides by Microsoft's responsible disclosure guidelines, but posts the length of time since it reported a vulnerability to the software giant on a special page on its Web site. The top-rated flaw on the company's Web site was first reported to Microsoft almost six months ago.

The detente also makes manufacturers look good in terms of the lag between the public warning of a flaw and the release of a patch. For example, a year-old study by Forrester Research gave a nod to Microsoft

for minimizing the window of vulnerability, compared with most Linux distributions. It's a direct side-effect of the software giant's ability to convince security researchers to play ball, despite expectations.

"The general consensus in the developer community is that one would like to help the open-source projects rather than to torpedo them," said Laura Koetzle, vice president and research director of Forrester Research and the author of the report. "Whereas the temptation with a large faceless company is to disclose early and hurt them."

The dispute over disclosure goes to the heart of an old question: Is it responsible to give details of a threat, if the warning puts even more people in danger?

Those concerns drove a discussion on the mailing list for the kernel of Linux last week. A suggestion that a contact point be created to focus on security issues in the kernel, or core of the open-source operating system, immediately blossomed into a debate about whether that list should be private or public.

In addition, the debate centered on the question of whether the vendor-centric security list, Vendor-Sec, takes too much time to fix important flaws.

"It should be very clear that no entity...can require silence or ask anything more than 'Let's find the right solution,'" Linus Torvalds, the original creator of Linux, said in the discussion. "Otherwise, it just becomes politics."

In general, though, the open-source world, which has to deal with public development models, has largely learned to embrace security researchers.

"If we get a report from the outside, it is up to the one who finds the vulnerability to decide what happens to it," said Roman Drahtmueller, head of security for SuSE Linux, Novell's version of the operating system.

Microsoft, however, would rather work in secrecy with flaw finders to help prepare a fix. With the public spotlight on its security glitches and with hundreds of millions of users relying on its products, the software giant is very systematic in its approach to patching.

"It is best for customers, because we have a chance to provide updates before a large segment of the black hat community gets to make use of the vulnerability," said Microsoft's Kean.

Flaw finders who do not play by the rules don't get credit in Microsoft's security bulletins and are rebuked in press releases, among other sanctions.

"Microsoft is concerned that this new vulnerability in (product is named) was not disclosed responsibly to Microsoft, potentially putting computer users at risk," the software maker has typically written in e-mailed statements about vulnerability disclosures.

Despite the efforts of Microsoft and others, many researchers still don't feel that the companies take their findings seriously. While some security software sellers have lauded Apple for its response to vulnerability discoveries, an independent researcher gave the company a thumb's down.

"It's really been like pulling teeth dealing with them over the years," said the researcher, who asked not to be identified. "I know a lot of folks that have found vulnerabilities in their stuff that pretty much refuse to deal with them."

Even if security researchers play ball with software makers and hold off on making vulnerabilities public, that might only engender a false sense of security, said flaw finder Aitel. He said that a small, but significant, number of malicious programmers could discover such security holes independently and abuse them.

"We don't feel that we are finding things that are unknown to everyone else," he said. "I am not special because I can run a debugger. Others can find--and use--these flaws."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 90 Talkback(s)
If they Know about it.Customers Should know about it!
HI all:
Reading the subject about flaw finders and Microsoft, as well as other software makers.Should the Public be informed of Flaws and holes in software Products?Or should Only the Software comp... (Read the rest)
Posted by: a8a09923@... Posted on: 02/18/05 You are currently: a Guest | | Terms of Use
IMHO...  BitTwiddler | 01/26/05
Absolutely agree  johnnybluenote | 01/26/05
Ok, if a reasonable time is 1 week.  DonnieBoy | 01/26/05
Nope, it was already decided  Roger Ramjet | 01/26/05
30 days is too much. You don't need 30 days unless you have spagetti code.  DonnieBoy | 01/26/05
No, 7 days is not enough  TechType | 01/26/05
"a deal ... ...between the vendors and the hackers"  el1jones | 01/26/05
The problem with that approach...  Michael Kelly | 01/26/05
That's why I said...  BitTwiddler | 01/27/05
Agree completely  FilledOut | 01/26/05
Key thought  Mack DaNife | 01/26/05
A corollary to your key thought  Judas I. | 01/26/05
Yes,l way too many problems with keeping things secret.  DonnieBoy | 01/26/05
30 days - already decided  Roger Ramjet | 01/26/05
So...  Mack DaNife | 01/26/05
It's just identity theft dude..  Jeff Spicoli | 01/26/05
My point exactly!  Mack DaNife | 01/26/05
Businesses ALWAYS couch it in those terms  Jeff Spicoli | 01/26/05
Yeah, and...  rapson | 01/26/05
They ain't, and that's why ...  Judas I. | 01/26/05
OMG  Mack DaNife | 01/26/05
Whoever made that 30 day pact ...  Judas I. | 01/26/05
It's not a pact...  OldeTimeGeek | 01/26/05
I see you have never tested patches...  Confused by religion | 01/26/05
Yer wrong, Milly, ...  Judas I. | 01/26/05
So it takes you  ksj99 | 01/26/05
Boo, hoo, poor widdle Microsoft!  Judas I. | 01/27/05
I like that one  IT Scion | 01/28/05
30 Days  Roger Ramjet | 01/26/05
What?  Judas I. | 01/26/05
Whoa there partner  Roger Ramjet | 01/26/05
Not that I am going to "spit the bit" here, Roger, ...  Judas I. | 01/26/05
OTOH  Roger Ramjet | 01/27/05
OTotherOH:  Judas I. | 01/27/05
I understand...  Mack DaNife | 01/26/05
OLAs  Roger Ramjet | 01/27/05
30 days??? reasonable???  rchasse2002 | 01/26/05
Not reasonable  Roger Ramjet | 01/26/05
IMMEDIATE and full disclosure is the best long-term solution  Root User | 01/26/05
One sided  Roger Ramjet | 01/26/05
One Sided Heck...  rchasse2002 | 01/26/05
There is a difference  rapson | 01/26/05
Well  IT Scion | 01/26/05
LOL  Roger Ramjet | 01/27/05
Not one-sided at all  Root User | 01/26/05
Evilution  Roger Ramjet | 01/27/05
Re: Evilution  Root User | 01/27/05
White Hats  JimSatterfieldW | 01/28/05
So you're saying...  rapson | 01/27/05
Re: So you're saying  Root User | 01/27/05
Got it  rapson | 01/28/05
Wow  IT Scion | 01/27/05
Re: Wow  Root User | 01/27/05
k...  IT Scion | 01/28/05
whoa, nellie !  culebra | 01/27/05
p.s.  culebra | 01/27/05
Re: whoa, nellie!  Root User | 01/27/05
I agree  culebra | 01/27/05
"Accountable" is the right word here  Root User | 01/27/05
Truth be known - this is an open society.  BetaMale | 01/26/05
Not so brilliant  IT Scion | 01/26/05
Who is the most irresponsible???  rchasse2002 | 01/26/05
I would say...  rapson | 01/26/05
But  IT Scion | 01/26/05
259.9MB, 1126 files, 260 folders  sam8988378 | 01/26/05
Not quite  rapson | 01/26/05
They still owe it to their customers to be honest  Michael Kelly | 01/26/05
I won't dispute that  rapson | 01/26/05
True, no one forces a criminal act...  Michael Kelly | 01/26/05
OK  rapson | 01/26/05
BS  Omch'Ar | 01/26/05
Not sure  rapson | 01/26/05
To make that point  ksj99 | 01/26/05
RE : 259.9MB, 1126 files, 260 folders  Unemployed IT Guy | 01/28/05
The only thing irresponsible...  Omch'Ar | 01/26/05
Secrecy is never a good thing  Gregory.J.Bradley@... | 01/26/05
Point by point  IT Scion | 01/26/05
What do you want  Roger Ramjet | 01/27/05
I Agree with Aitel  robradina@... | 01/27/05
Almost not worth it but  IT Scion | 01/27/05
Puzzled...  robradina@... | 01/27/05
and what about the negative consequences?  culebra | 01/27/05
Well  IT Scion | 01/28/05
careful with that axe, Eugene  culebra | 01/27/05
Aitel flaw finder  aljulong@... | 01/27/05
time and trouble...  liberalenextrema@... | 01/27/05
Something the "rebels" avoid discussing...  David A. Pimentel | 01/28/05
Flaw finders go their own way  marcvridenour | 01/28/05
Can a question be a non-sequiter?  jpslocum@... | 01/31/05
If they Know about it.Customers Should know about it!  a8a09923@... | 02/18/05

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and