Are vulnerable times responsible times?

(continued from previous page)

"Any individual or organisation that behaves in a way that potentially puts ... customers at risk is a huge concern," he says. "We continue to urge security researchers to disclose vulnerability information responsibly and allow customers time to deploy updates so they do not aid criminals in their attempt to take advantage of software vulnerabilities."

Greg Shipley, chief technology officer of Chicago-based security outfit Neohapsis, holds back judgement but says the existence of private vulnerability sharing clubs like Aitel's raise some serious ethical questions.

There are millions of unknown vulnerabilities and the software manufactures should not be forced to purchase these. How much are they worth? Who sets this value?
-- Ron Gula, creator of Dragon IDS
"When you start talking about advanced release times, publishing exploit code, and introducing a mercenary angle to what is essentially ... a public quality assurance process, you start entering some really murky waters," he says.

The trade in information that allows the buyer to easily penetrate computer networks is dangerous, Shipley argues. "If it simply boils down to the highest bidder, we're in for some real problems."

"If anyone with a few dollars can afford to 'buy into' such an information ring and get access to tools that blow past most corporate defences, what's to stop some truly malicious folks from using that information for truly evil purposes?" Shipley asks.

"Zero-day", or unpublished security vulnerabilities are becoming the "tactical nukes" of cyberspace, Shipley argues; the Holy Grail. He doesn't want to see them falling into the wrong hands.

But Ken Pfeil, chief security officer at Capital IQ, a web-based provider of financial data services, isn't alarmed. Services offered by companies like Immunity are ethical, "as long as they hold the information to themselves and sign the members to a non-disclosure agreement". Still, he does acknowledge the sensitive information may "leak", but that's not Aitel's fault, he says. Vulnerability information leaks have sprung from other sources, like the Carnegie Mellon University-based research outfit CERT, which receives US government funding.

"No one holds CERT accountable when a member leaks information, so why would this be any different?" Pfeil asks.

Perhaps some in the security industry are merely annoyed Aitel has the gumption to turn vulnerabilities into cash in such a controversial way. Having access to vulnerability information if you're a researcher seems to be a lesser sin in the eyes of many. It's ironic, considering some prominent researchers have been known to dabble in illegal activity.

Continued ...

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal That sinking Tcard feeling
    There's something terribly unsettling about realising that the NSW Government is considering hiring a company to build a new electronic ticketing system which has already put it through the legal wringer for the system's predecessor.
  • Array The challenge of government 2.0
    The Government 2.0 Taskforce released its draft report last week, and its recommendations for Open Government almost reads like a manifesto. Stilgherrian's guest on Patch Monday this week is the chair of the Taskforce, Nicholas Gruen.
  • Array The people's NBN, now with 1001 uses
    Faced with a renewed threat in newly-appointed Tony Abbott and unknown-quantity communications portfolio ankle-biter Tony Smith, Stephen Conroy responded this week in the way any politician would: he gave lots, and lots, and lots of speeches.
  • More blogs »

Tags

Back to top

Featured