<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>CastleCops : Disclosure</title><link>http://msmvps.com/blogs/castlecops/archive/tags/Disclosure/default.aspx</link><description>Tags: Disclosure</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>You'll take your full disclosure pill, and like it.</title><link>http://msmvps.com/blogs/castlecops/archive/2005/04/27/44737.aspx</link><pubDate>Wed, 27 Apr 2005 05:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:44737</guid><dc:creator>paul</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/castlecops/rsscomments.aspx?PostID=44737</wfw:commentRss><comments>http://msmvps.com/blogs/castlecops/archive/2005/04/27/44737.aspx#comments</comments><description>&lt;P&gt;Just a month ago now, &lt;A href=http://www.computerworld.com/printthis/2005/0,4814,100637,00.html&gt;legal threats&lt;/A&gt; by Sybase directed at NGS Software were used to&amp;nbsp;cease the full disclosure of eight holes in its product.&amp;nbsp; NGS Software disclosed their findings to Sybase and advised them its public disclosure would occur three months after that.&amp;nbsp; Sybase didn't like that, but it all worked out in the end after they reached a settlement.&amp;nbsp; Could it be that Sybase didn't have enough time to warn their customers about the upgrade?&lt;/P&gt;
&lt;P&gt;
&lt;BLOCKQUOTE&gt;
&lt;HR&gt;
Responsible disclosure of software flaws by vulnerability researchers has "significantly improved" the security of products, Powers said. 
&lt;HR&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I concur.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;So what is responsible disclosure?&amp;nbsp; Talk to the security mailing lists and there is a difference of opinion.&amp;nbsp; Even Wikipedia references &amp;#8220;full disclosure&amp;#8221; as &lt;A href=http://en.wikipedia.org/wiki/Full_disclosure&gt;controversial&lt;/A&gt;.&amp;nbsp; I'd like to see the world take on the stance of &amp;#8220;responsible disclosure&amp;#8221;:&lt;/P&gt;
&lt;P&gt;
&lt;BLOCKQUOTE&gt;
&lt;HR&gt;
Some believe that in the absence of any public &lt;A title="Exploit (computer science)" href="http://en.wikipedia.org/wiki/Exploit_%28computer_science%29"&gt;exploits&lt;/A&gt; for the problem, &lt;I&gt;full and public disclosure&lt;/I&gt; should be preceded by disclosure of the vulnerability to the vendors or authors of the system. This private advance disclosure allows the vendor time to produce a fix or workaround. This philosophy is sometimes called "&lt;A class=new title="Responsible disclosure" href="http://en.wikipedia.org/w/index.php?title=Responsible_disclosure&amp;amp;action=edit"&gt;responsible disclosure&lt;/A&gt;". 
&lt;HR&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'd like to take that a step further, and break it down:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Report the vulnerability to the vendor with a suggested patch, 
&lt;LI&gt;Obtain a response from the vendor and establish a patch release and public disclosure timeline in that order, 
&lt;LI&gt;Vendor releases tested patch, 
&lt;LI&gt;Full public disclosure is made with credits.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;If the vendor does not respond, make a couple more attempts and then release the disclosure.&amp;nbsp; Mark it as &amp;#8220;vendor MIA&amp;#8221; or similar.&amp;nbsp; Note, the suggested patch is still included in the release.&lt;/P&gt;
&lt;P&gt;If a suggested patch is unavailable, find someone who can help you.&amp;nbsp; If you cannot produce any of the above, list that in your disclosure timeline.&amp;nbsp; Show proof you have been responsible in trying to contact the vendor and/or produce a patch.&amp;nbsp; If the above fails, and there is nothing left except for the vulnerability report, then by all means have at it.&amp;nbsp; Release the report and let the chips fall where they may.&amp;nbsp; At least you've shown due diligence.&lt;/P&gt;
&lt;P&gt;Timeframe?&amp;nbsp; Is three months too long?&amp;nbsp; Is eight hours too short?&amp;nbsp; Personally, I've always kept mine to below a month.&amp;nbsp; The idea is to get a patch out there quickly.&amp;nbsp; The less holes available for poking, the better.&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=44737" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/castlecops/archive/tags/Disclosure/default.aspx">Disclosure</category></item></channel></rss>