In the news
Here are some thoughts on the so called "Responsible Vulnerability
I am posting to this mailing list because there are some people from
interesting domains (not counting script kiddies and seattle users) and
because for a number of reasons I do not post to Bugtraq anymore.
This draft RFC is quite similar to seattle users's rant at
It's no surprise this user Scott Culp has given "constructive comments" to the draft RFC (Section 6 of the original draft).
A *very good reading* for the above topic is
written by Jericho (security curmudgeon)
Anyway I disagree with at least the following from the draft RFC:
3.6.2 Reporter Responsibilities
1) The Reporter SHOULD recognize that it may be difficult for
Vendor to resolve a vulnerability within 30 days if (1) the
is related to insecure design, (2) the Vendor has a diverse
hardware, operating systems, and/or product versions to support,
(3) the Vendor is not skilled in security.
2) The Reporter SHOULD grant time extensions to the Vendor if
Vendor is acting in good faith to resolve the vulnerability.
Here are my arguments in no particular order:
*) this may allow vendors to label reporters as "RFC compliant
irresponsible" while shifting the focus from their buggyware.
Example: Recently Cigital disclosed a flaw in a claimed feature in
microsoft's compiler. While in public forums microsoft claimed this is not
a flaw but a feature, at http://news.com.com/2100-1001-838096.html
the media wrote
Some security experts criticized the quick public announcement
So the vendor denies this is any kind of bug yet to avoid negative publicity
and instead the reporter is labeled "irresponsible"
*) The community should encourage *disclosing* bugs even if they are
disclosed. People with skills will always *find* bugs while they may
disclose* them. Ever thought how many 0days are out there?
And some high profile sites continue get defaced.
*) I don't find it logical to be "responsible" to sell undertested and
underquality software and to be "irresponsible" to disclose a bug.
*) Any vendor who sells software with disclaimers which disclaim any
liablity SHOULD NOT use the word responsible.
*) I personally have disclosed vulnerabilities since 1996 about Oracle, IBM,
Microsoft,Netscape, FreeBSD, OpenBSD, Sun and others.
Only one the above has claimed I am irresponsible.
Just my 2 stotinki,