6 ms·
Early access to the knowledge of vulnerabilities is just good customer service when you're talking about your biggest customer who is also very security conscio
by trotsky 13y ago
Early access to the knowledge of vulnerabilities is just good customer service when you're talking about your biggest customer who is also very security conscious. It allows them to protect themselves. The fact that the same knowledge can facilitate developing of offensive payloads is unfortuneately unavoidable - but that doesn't mean that's the purpose of the program or that it should preclude any early sharing at all.
Most of the time (with other vendors, say cisco) these early warnings include general descriptions of the problem and remediation steps - but not explicit descriptions or code patches. While that can be enough to point someone on the right track and develop an exploit for it (depending on a ton of unknown factors), I'd say that 99% of the time the exploit doesn't actually get written until the author can get their hands on the actual patch, so they can see exactly what code was changed. Many of these vuln disclosures are enormously generic in scope. think "a parsing vulnerability in an xml format" and remediation - don't allow connections to xxx port or turn off major software component y.
It wouldn't surprise me if the us government gets pre-public access to inofrmation that makes it easy to weaponize 0-days (what the hell is the zero day initiative, anyway?) but you'll have to do a hell of a lot more digging and analysis before you could convince me that this is one of them.
- liotier 13y ago> Early access to the knowledge of vulnerabilities is just good customer service Customers who don't have early access might object, especially if they are foreign governments who might sometimes have competitive issues with the USA - which includes pretty much everyone.