Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Prime Choice
Steve Ballmer says everything would be fine if security researchers would "just be quiet."

He actually makes a very good point. Security researchers would be doing a much greater service to society if they submitted their findings to Microsoft for private correction so that the patch could be released before the public was even aware the hole had been found. That way, you got the patch before any of these foreign hackers were attacking you.

And it's always these foreign "security firms" that open source the exploit if not the viral code itself to the general public leaving Microsoft in a "you have to be kidding, who are you supposedly helping here" position, one that certainly seems understandable.

However some feel that the open source release of viral code before notification of Microsoft or other vendor is a positive thing. There are as we've come to learn those that wish as much ill harm on Microsoft as possible, and there is also a group that feels the virtual terrorists are already pulling out all the stops to get viral code in effective use by open sourcing it to the internet, but that ultimately that has helped the overall security of the internet by already requiring the fastest possible responses to emerging threats.

I disagree with anyone who supports publicly releasing exploits much less open source code of viral technology before vendor notification, as they are crossing the line between being a white hat hacker and a black hat one.

49 posted on 01/28/2004 5:33:52 PM PST by Golden Eagle
[ Post Reply | Private Reply | To 42 | View Replies ]


To: Golden Eagle
"He actually makes a very good point. Security researchers would be doing a much greater service to society if they submitted their findings to Microsoft for private correction so that the patch could be released before the public was even aware the hole had been found. That way, you got the patch before any of these foreign hackers were attacking you. "

Not entirely true, Ballmer ALSO doesn't want exploit code or details to be released. The argument against this approach is the same as the argument against gun control. It is utterly critical that specific technical detail be released, and Microsoft is doing nothing but playing CYA at the expense of their customers.
53 posted on 01/28/2004 5:45:27 PM PST by adam_az (Be vewy vewy qwiet, I'm hunting weftists.)
[ Post Reply | Private Reply | To 49 | View Replies ]

To: Golden Eagle
I disagree with anyone who supports publicly releasing exploits much less open source code of viral technology before vendor notification

The law of unintended consequences could affect your argument.

Specifically, this would encourage software vendors to write sloppy code because they can always fix it later.

73 posted on 01/28/2004 7:47:17 PM PST by staytrue
[ Post Reply | Private Reply | To 49 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson