Feeds

Software biz urges tougher bug disclosure ‘rules’

Timeline for security vuln reporting

  • alert
  • submit to reddit

Protecting against web application threats using SSL

A group of 11 of the largest software companies and computer security firms released the first public draft of a proposed bug disclosure standard on Wednesday, and asked the security community for comments.

The 37-page document sets out a detailed timeline for security vulnerability reporting, and standardizes the interactions between security researchers who find bugs and the software companies who write them. The group hopes to see the final version of the plan gain widespread industry acceptance.

"The meat of it is all about the process -- how people come around to handling everything where they can talk to each other," says Scott Blake, a VP at security software firm BindView, an OIS member.

The OIS officially formed in September of last year, but has its roots in a private Microsoft-hosted security conference held in Silicon Valley almost a year earlier. Member companies are Microsoft, @stake, BindView, SCO, Foundstone, Guardent, Internet Security Systems, Network Associates, Oracle, SGI and Symantec. (Symantec publishes SecurityFocus.)

A chief objective of the organization is to encourage a limited form of public warning that withholds details useful to hackers.

To that end, the plan would curtail the common but controversial practice of publicly releasing proof-of-concept or "exploit" code that demonstrates a security hole. Researchers following the policy would not be able to release exploits, nor provide "detailed technical information such as exact data inputs, buffer offsets, or shell code strategies" to the general public.

That prohibition is loosened somewhat thirty days after the vendor releases a patch. At that point the bug-finder could distribute exploit code or technical details to "organizations such as academic institutions that perform research into secure software development techniques."

Whether or not that includes popular forums and mailing lists like Bugtraq, NTBugtraq and Full Disclosure is a gray area, says Blake, that the group deliberately left open to interpretation.

"It's one of the areas I suspect we're going to get comments on," Blake says. "That's one of the reasons we're putting this thing out for public comment, because we want people to come back with that kind of feedback."

The group is accepting comments by e-mail for thirty days, ending July 4th, and expects to release the final plan at the Black Hat Conference in Las Vegas later that month. © SecurityFocus

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Jihadi terrorists DIDN'T encrypt their comms 'cos of Snowden leaks
Intel bods' analysis concludes 'no significant change' after whistle was blown
Home Depot: 56 million bank cards pwned by malware in our tills
That's about 50 per cent bigger than the Target tills mega-hack
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Critical Adobe Reader and Acrobat patches FINALLY make it out
Eight vulns healed, including XSS and DoS paths
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.