How to Deal With Vulnerabilities

This is always a fairly emotional theme. What is better to protect the ecosystem? Public or private disclosure? Should somebody paying for vulnerabilities or not? Is a vulnerability auction ethical or not?

I know that there are numerous views on that and I do not want to debate them here and now. What I just want to do here, is to show Microsoft’s position:

Since a long time Microsoft is working with the researcher community in close collaboration and my understanding is that the researcher community is fairly impressed with what we do, once they get the opportunity to look behind the scenes. One of the outcomes of this outreach is Bluehat – a Microsoft internal event where the researcher talk to our developers. A very and interesting and insightful get together.

When it comes to handling vulnerabilities, I guess you know Microsoft Security Response Center – the group within Microsoft chartered with handling security vulnerabilities. The policies behind working with the researcher community is two-fold:

For me, the joint goal between researcher and vendors has to be to protect the ecosystem against the criminals. And with ecosystem I mean not only the big enterprises, having security teams which are able to work on detailed vulnerability information but small and medium businesses as well as the consumer like my mom and dad as well. Therefore we think that the point above help to meet the requirements.

What are your thoughts on that?

Roger

Related posts:

  1. Vulnerability Disclosure to Compete?
  2. Selling Vulnerabilities and Ethics
  3. Microsoft and Adobe: Collaboration Against Threats
  4. Attacks on the Windows Help and Support Center Vulnerability (CVE-2010-1885)
  5. H1 OS Desktop Vulnerability Report – Get It Now
This entry was posted in Incidents, Microsoft, Processes and tagged , , . Bookmark the permalink.

One Response to How to Deal With Vulnerabilities

  1. Pingback: Tweets that mention How to Deal With Vulnerabilities | Roger Halbheer on Security -- Topsy.com

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>