#1 - In excess of 95% of all security patches/updates/workarounds implemented on a windows platform are those that come through the automatic update process
#2 - Upon disclosure, the universe of script kiddies which never, ever, would have discovered this security exploit on their own have now been handed a gift which they will exploit with their rudimentary skills.
I'm a strong proponent of responsible disclosure, and really believe that it has made our platforms much, much more secure, obviously in an absolute sense, but also, in a relative sense.
But, responsible disclosure involves giving the vendor a reasonable amount of time - typically one or two patch cycles, prior to releasing the exploit. Anything other than that is juvenile and besmirches the community of responsible security researchers.
You will, on the other hand, find plenty of people with real reputations in the industry at stake (unlike yours, which is influenced not one whit by anything you say about disclosure) who will be happy to explain why "responsible disclosure" is damaging the industry. It's not even a hard argument to make. The dollar value of a reliable Windows remote is too high to pretend that bona fide researchers are the only people who will find them. Meanwhile, because product managers at large vendors are given the latitude to fix problems on the business' schedule instead of the Internet's, people get to wait 6-18 months for fixes to trivial problems.
Personally, without wading into "responsible" vs. "full" disclosure, I will point out that vulnerability research has made your systems more secure; the manner in which the vulnerabilities were uncovered has very little to do with it. You are more secure now because vendors and customers pay to have software tested before and after shipping it.
(My personal beliefs don't often enter the picture; I represent the interests of my clients, almost all of whom would rather fix things on their own schedule).
This is an issue that reasonable and responsible people disagree about.
But I am interested in the argument about "responsible disclosure" damaging "the industry" is one I would like to hear. Since it's not hard to make, it should be easy to repeat. I'm not sure what "the industry" is here, though.
Some other strange parts of the response: "The dollar value of a reliable Windows remote is too high to pretend that bona fide researchers are the only people who will find them."
Why accuse someone of pretending? I would not be surprised to find that you are right, but you should be able to point at data.
Another problem is use of the passive voice: "product managers at large vendors are given the latitude to fix problems on the business' schedule instead of the Internet's"
Who gives them that latitude?
The process of "responsible disclosure" gives product managers latitude, because it effectively dictates that researchers can't publish until the vendor releases a fix. The vendors almost always decide when to release fixes.
When a researcher publishes immediately, vendors are forced to fix problems immediately. A small window of vulnerability is created ("small" relative to the half life of the vulnerability, which depends on all sorts of other things) where less-skilled attackers can exploit the problem against more hosts.
On the other hand, in the "responsible" scenario, many months will invariably pass before fixes to known problems are released. During that longer window, anybody else who finds the same problem (and, obviously, anyone who had it beforehand) can exploit the vulnerability as well.
Furthermore, full disclosure creates a norm in which vendors are forced to allocate more resources to fixing security problems, instead of waiting half a year or more. This costs vendors. But the alternative may cost everyone else more. It depends on how well-armed you think organized crime is.
Finally, Robert, there's the issue nobody ever seems willing to point out. If you disclose immediately, lots of people can protect themselves immediately: by uninstalling or disabling the affected software.
You're still using the passive voice. It's not as if "product managers" are some well-defined group of people. For that matter, neither are "bona-fide security researchers".
When I used the word "researcher" in scare quotes before, I wasn't trying to say this guy is quack. He obviously isn't. But using the word researcher is overblowing things. In reality, these guys are inspectors. They find real problems, and that is important, but very few of the problems they find are novel in nature. We do continually get the same types of defects reported, so something is wrong, but it has nothing to with reporting strategies. Change the way we write software--that would be actual research.
The disclosure trade-offs you describe sound plausible, but don't account for the fact that an inspector may find an issue no one else has discovered. They are also backed up by zero data.
"Bona-fide researchers" are people who find and report flaws in good faith, as opposed to researchers who find flaws and sell them to organized crime. I use the term "bona-fide" because that's what it means: "good faith".
I use the term "researcher" because that's the convention.
That's not why you put scare quotes around the term.
An infinitessimal fraction of all computer crime is ever seriously investigated. If you want hard stats, no argument I can make will satisfy you. I'm fine with that.
2.) Ah, organized crime, but none of it is ever reported. Lack data much? For an "industry" that supposedly values transparency, the total absence of data seems odd.
3.) Why are you telling me why I put scare quotes around the term "researcher"? I told you why. I'm not lying.
http://en.wikipedia.org/wiki/Humpty_Dumpty#In_Through_the_Lo...
2) You won't find that kind of news on CNN, but it's out there if you know where to look. Try DarkReading or F-Secure's blog, just to get started. There are many botnets out there right now. Even some controlled by Russian mobsters. There are places where you can buy, sell & trade credit card numbers. There's a TON of crime out there, but for people who don't deal with it, all you hear is the occasional, "Company X had a data breach affecting approximately Y users. A company spokesman wants to assure you that everything is all right and that the very same company that allowed this breech to happen will make sure that it quickly vanishes from the public eye."
Finally, you don't know Thomas as you indicated in a post further up, you might want to read this:
http://www.darkreading.com/security/management/showArticle.j...
In case you're wondering, it's really not uncommon for people who deal with computer security to take the time to find out who they're talking to online. You might be surprised at how often it proves useful. And I'm practicing what I preach here, because I only know him by reputation.
I define computer crime as a successful network intrusion where an attacker gains access to the internal network, which occurs at a frighteningly high level.
It's making me feel weird as well.
A) Security Researchers should not disclose
vulnerabilities.
B) Security Researchers should not disclose
vulnerabilities before the vendor has a
chance to patch them.
C) Security Researchers should aggressively
disclose on a 30-60 day time frame.
D) Security Researchers should disclose within a week.
I'll presuppose that your answer will be "E - it depends" - so let's restrict it to this _particular_ vulnerability.My answer is C), but only because I realize that the squeaky wheel _really_ gets the grease, and that the threat of disclosure really, really inspires developers to Lab, Replicate, Solve, and deploy a fix. My answer is not D), because I believe more harm is done by disclosing vulnerabilities where there is _no chance_ of a patch being completed in time. Tavis Ormandy clearly believed the answer was D) in this case.
Also, of all vendors, Microsoft is actually pretty good (not perfect) about getting regular security patches out on a monthly basis - I'd have to believe that they probably prioritized this one fairly high.
I think the world would be a better place if everyone would do (D).
I agree with you about Microsoft.