CERT to disclose software flaws

NEWS It may herald the end of a fight that has inflamed the security community for more than a decade: the Computer Emergency Response Team, or CERT, has endorsed a policy of open flaws in software that could affect security. The CERT Coordination Centre, which tracks current security threats and publishes advisories to the public, will continue its policy of not publishing any code for exploiting flaws. It will, however, make software security flaws public within 45 days. The change, announced this week, signals that traditionally conservative organisations are now leaning towards publicly releasing information about software vulnerabilities rather than remaining silent. The industry "is moving away from polar extremes", said Shawn Hernan, team leader for vulnerability handling for the CERT Coordination Centre, a part of the Carnegie Mellon University. "There is a philosophy that endorses immediate and complete disclosure and there is a philosophy that endorses complete and utter silence. The trend I see is towards the middle of that." In the end, the change may mean little difference for CERT members, but increase the pressure on companies to produce better and more secure software. Three months ago, Marcus Ranum, a well-known security expert and founder of the intrusion-detection software maker Network Flight Recorder, strongly urged a gathering of network professionals to keep secret any security holes found in Internet software and stop creating tools to exploit the holes. "Full disclosure is creating armies and armies of script kiddies," said Ranum at the Black Hat Security Briefings in July. He went so far as to call the creators of hacking tools "weapons dealers" who aren't really concerned with security. "Distributing [those] tools is not helping," he said. Yet, while Ranum is well-known in the industry for his black-and-white views on disclosure, most security professionals fall into a grey area. One such person is Elias Levy, chief technology officer for industry information site SecurityFocus.com. "I think that over the last ten years, full disclosure has moved from an extreme point of view to the accepted point of view," he said. On its mailing list, SecurityFocus regularly releases information and, sometimes, source code to illustrate the exploit. "Of all the issues of full disclosure, exploits are the most contentious," he said. While many claim exploits -- source code that illustrate how any programmer could take advantage of a vulnerability -- only hurt the industry by teaching the enemy, Levy stresses that they are frequently necessary. "In many cases, they are the best way to explain a problem," he said. "In other cases, an exploit is necessary because a vendor will not try to solve a problem without proof that someone could take advantage of it." That last behaviour was what another "grey hat" group, known as The L0pht -- who now make up a large part of the research arm of @Stake -- poked fun at on their Web site with this exchange: "'That vulnerability is entirely theoretical.'-- Microsoft L0pht, making the theoretical practical since 1992." Yet, companies have a legitimate gripe. Media reports abound with security groups that release vulnerability information and exploit code soon after -- or at the same time that -- they notify the flawed software's creator. A case in point: on Thursday, Bulgarian bug hunter Georgi Guninski publicised a vulnerability in Microsoft's Internet Explorer 5.5 that could allow an attacker the ability to read, write and execute specific files on a PC. Guninski gave Microsoft only 24 hours before going public with the flaw. The CERT Coordination Centre hopes its latest move -- in conjunction with talks with some of the major security houses -- will dampen some of the fame-seeking in the industry. "We are trying to help build an ethos of how to release vulnerability information," said Hernan. "The public has an interest in knowing what the risk is and the vendors have an interest in having enough time." CERT promises to release the name of whoever discovers a bug when they release their advisory after the 45 day wait. "This is an attempt to get the community to behave in a rational sort of way," he said. Take me to Hackers To have your say online click on the TalkBack button and go to the ZDNet News forum. Let the editors know what you think in the Mailroom. And read what others have said.

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

georgiox

love the LHC info. Keep up the good work. May God bless all in volved.

3 hours ago by georgiox on LHC to run for longest continuous period
sgardia

You are quite right. HDS has not been marketing their products well. USPV is miles ahead in terms of ease of use and technology on enterprise...

7 hours ago by sgardia on Will the SUN set on Hitachi Data Systems OEM relationship?
apexwm

Fedora is the same way as well. The yum update system uses "presto" which shrinks the amount of data needed for download. It's a great system....

18 hours ago by apexwm on Can you believe it - 2765 kB will be freed?
cybfor

Updated ID cards considered for 2012: [zdnet.co.uk] The government is considering introducing a new generation of ID... http://dlvr.it/KpBZ

cybfor

Google, Viacom trade blows in YouTube copyright spat: [zdnet.co.uk] Google and the US media giant Viacom have issued... http://dlvr.it/Knht

CIMITL

Be sure to include an audio option - eg. a beep tone - to intensify and reiterate the action. This will greatly benefit some consumers and give...

20 hours ago by CIMITL
DataSecurityUK

Data disposal is really important to get right. There are standards set by UK and US federal governments to ensure that data is kept secure. If...

21 hours ago by DataSecurityUK
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

22 hours ago by chaycon1 on BT launches 40Mbps fibre-based broadband
chaycon1

Online Fiber Optic Certification Join a talented group of professionals, who are dedicated to Fiber Optic Networking technology. The online course...

22 hours ago by chaycon1 on Google to build gigabit broadband to the home
J.A. Watson

Hi Dava, I'm glad to hear from you, and glad that you see things from the other side. I think that is the most important point of the whole...

23 hours ago by J.A. Watson on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

please please please please please please kill that spam bot.

23 hours ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
253chelisa253

hi

24 hours ago by 253chelisa253 on How security will look in 10 years
lezlow

it is only greedy[microsoft]?

1 day ago by lezlow on Researchers break into BitLocker
dava4444

it didn't post the link it's 'Ubuntu 10.04 Lucid Lynx Beta-1 First Look' on youtube :) Dava

1 day ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi James I disagree, Ubuntu needs a GUI update and this one IMO is quite good. your pics show a low res. here's a high res. on YouTube* The...

1 day ago by dava4444 on Ubuntu 10.04 (Lucid Lynx) and the Latest Tempest
dava4444

Hi any news on the comment bot? knocking me back from my own blog is a bit cheeky lol *Mulder to Scully* "I think it has an agenda.." I know, I...

1 day ago by dava4444 on ZDNet UK: faster, smarter, still IT all the way
benny boy

if you look at the Brentwood exchange on samknows it servers 21,000 residential propertiesm, Lowestoft serves 31,000! Come on BT sort yourselves...

1 day ago by benny boy on BT fibre broadband coming to 69 more towns
pbreddit

[programming] H.264 - a sting in the tail http://reddit.com/bfu4q [zdnet.co.uk]

reddit

H.264 - a sting in the tail [programming] 13 points, submitted by zigzag [zdnet.co.uk] http://reddit.com/bfu4q

cybfor

Malware infects second Vodafone HTC phone: [zdnet.co.uk] A second Android-based HTC Magic from Vodafone has been... http://dlvr.it/KhKx

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now