This entry was posted on Thursday, August 7th, 2008 at 6:30 pm and is filed under General Category. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.
Microsoft to seek credit for finding vulnerabilities
|
|
LAS VEGAS–Microsoft is jumping into the responsible disclosure game.
The company announced at the Black Hat security conference on Thursday that it is formalizing its program of informing third-party software vendors of security problems with products that run on top of Windows.
“We’ve seen the threat environment change,” said Andrew Cushman, who runs the Microsoft Security Response Center.
Vista is more secure than XP and has fewer infections, he said. In addition, there are an increasing number of third-party exploits, and fewer browser-based exploits than in third-party software, he added.
The MSRC already reports vulnerabilities to other companies, but now it is asking for recognition in finding the vulnerability. Microsoft will not post advisories on any of the third-party security issues it finds, like it does with vulnerabilities found in its own software, Cushman said.
The issue of responsible disclosure is constantly being debated, with vendors often arguing that researchers are too quick to go public when they find a vulnerability and researchers countering that if they didn’t go public the vendors would drag their heels on fixing the problem.
“Microsoft is in a unique position to help in that dimension,” he said. “We bring a little different gravitas to the table. I think we can actually change the dynamic around responsible disclosure.”
Earlier in the week, Microsoft said it would be giving third-party vendors a sneak peek at the technical details of the vulnerabilities in Microsoft software before the company releases its monthly “Patch Tuesday” updates. The company also announced it would help companies prioritize the vulnerabilities in its updates.
See Also:
- Rebtel Goes 8 Crazy For China on Friday - 08/08/08
- Cyber security issues mirror those from the Civil War- official says
- Web 2.0 Company Offers Free Collaboration Portals
- Five Things Sunroom Owners Wish They’d Done Differently
- Five Things Sunroom Owners Wish They’d Done Differently
[Via CNET - News.com]
Leave a Reply
