Sunday | 31 August, 2008
Computerworld
Networking's greatest debates in Security
Classic debates include Immediate flaw alerts vs. Disclosing with patches, IDS vs. IPS and Perimeter security vs. inside security
Staff Writers (Network World) 29/10/2007 08:05:00

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15

    Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
    Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
  • +

    Toxic Mix or Bit of a Mixed Blessing? 31/12/2007 10:36:30

    “Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . ” The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare’s Macbeth, but even so it makes “for a charm of powerful trouble”
    "Eye of newt, and toe of frog, Wool of bat, and tongue of dog . . . " The inter-generational office brew of Boomer, Gen X and Gen Y may not be quite as odious as that of the three witches in Shakespeare's Macbeth, but even so it makes "for a charm of powerful trouble"
  • +

    Strategies for Dealing With IT Complexity 24/12/2007 10:30:47

    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
    Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

A look at the all time greatest controversies in the history of the networking industry.

Immediate flaw alerts vs. Disclosing with patches

What's safer, knowing there's a gaping hole that can be exploited in a software product even when there is no patch for it, or being told about the gaping hole once there is a patch?

That debate, heard since the dawn of software, pits the tell-all crowd arguing for "full disclosure" against those who argue for "responsible disclosure," a philosophy favoring greater discretion about software vulnerabilities in the hope that malicious hackers won't benefit from too much information.

But that assumes they don't already know anyway. And if the hackers know, then is it just the good folks who are in the dark? Such have been the powerful arguments on both sides, which grew louder in the 1990s as Microsoft Windows settled in for a long stay on the desktop and server, giving "script kiddies" armed with automated attack tools the ability to hit a lot with little effort over the Internet. It didn't help that Microsoft in the early days was in a blissful state of near-complete denial about software holes.

At the same time, security research was accelerating, with brash young firms like eEye Digital Security (founded in 1998) discovering vulnerability after vulnerability in Windows, and at the time, arguing for full discovery. Then the real impact of software vulnerability hit home for the entire world when the crippling computer worm named Code Red ripped across the Internet in 2001, exploiting a vulnerability in unpatched Microsoft ISS Web servers.

Although a server patch had been available for a month that could have stopped Code Red if applied to servers, the topic of disclosure grew ever more shrill as some accused eEye of revealing too much about Windows flaws.

In an attempt to find balance in the debate, a group calling itself the Organization for Internet Safety was founded in 2002 by Microsoft and others in the industry to come up with guidelines for responsible disclosure of software flaws. Last updated in 2004, the OIS guidelines say someone discovering a software flaw should discretely share that information only with the software vendor involved, allowing a minimum of 30 days to correct the problem.

But since then, the argument has only gotten more muddied as a thriving industry in the last few years has sprung up for selling information about vulnerabilities directly to security firms, which then market the vulnerability data to subscribers.

Some individuals who once backed the OIS guidelines say they're antiquated and only useful for protecting software vendors. "The OIS standards were a valiant effort, but in the end the OIS was designed to help vendors manage things on their end," says Terri Forslof, who helped craft the OIS guidelines when working in Microsoft's security-response center but joined a security firm re-selling vulnerability research.

Still, others vehemently disagree, saying responsible disclosure in which vulnerability research is shared first privately with the software vendor is ethical, while selling it to subscribers is not. "They're brokering information that makes the world less safe," says Kris Lamb, director of the X-Force research development at IBM's Internet Security Systems division. -Ellen Messmer

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Still Sneaking In: The Threats Your Security Tools Aren't Telling You About

Web 2.0 applications are all the rage, offering us tremendous value when it comes to collaboration and communication. They also open us up to new kinds of attacks however, and can cause problems in keeping systems and data secure. Read on to learn about the new attack methods and how you can defend yourself and your business.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links