On CHOW: Vegetarian Thanksgiving dishes
BNET Business Network:
BNET
TechRepublic
ZDNet

March 3rd, 2009

Why full disclosure is an important tool

Posted by Ryan Naraine @ 1:41 pm

Categories: Adobe, Arbitrary Code Execution, Browsers, Data theft, Denial of Service (DoS), Exploit code, Flash, Malware, Microsoft, Passwords, Patch Watch, Punditocracy, Responsible disclosure, Zero-day attacks

Tags: Disclosure, Adobe Systems Inc., Tool, Productivity, Security, Ryan Naraine

Guest editorial by Danny Quist

This latest Adobe vulnerability has created a stir on some of the closed mailing lists regarding full disclosure. While I would have liked to think that this debate was over a long time ago, I now realize that everyone has disagreed to disagree.

On one side we have the people that are doing remarkable work by researching these flaws, disclosing them with appropriate warning to the vendors, and letting the public know about the problems. On the other side of the argument are the limited disclosure people.

[ SEE: Adobe swings and misses as PDF abuse worsens ]

The advocates of limited disclosure are excellent researchers who I know and respect. It floors me to think that it is acceptable for vulnerabilities to be left unpatched for a serious amount of time. I consider 90 days to be entirely too long to patch a vulnerability. The fact that Adobe said that a patch would be issued 18 days after the public disclosure is highly irresponsible.

[ SEE: Critical Adobe Flash Player patch coming ]

You can disagree with full disclosure, but it is a useful motivational tool. Microsoft responded well to their problems. They created a security development process that is unparalleled in the world. Adobe, it’s time for you to step up as well. Limited or closed disclosure creates complacency, which amounts to willful neglect.

I wish there was some other way than full disclosure to motivate vendors. Unfortunately it is the only method available that has a proven track record of working.

* Danny Quist is the CEO and co-founder of Offensive Computing.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
RE: Why full disclosure is an important tool
Advocates of limited disclosure tend to conveniently forget that in the past some companies have sat on known vulnerabilities for YEARS before fixing them.

As the article says, full disclosure ... (Read the rest)
Posted by: Uncle Stoat Posted on: 03/05/09 You are currently: a Guest | | Terms of Use
offensive is definitely what it is  Narr vi | 03/04/09
RE: Why full disclosure is an important tool  Uncle Stoat | 03/05/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and