About Me

Archive

Archive

Read More

Blogs

Feeds & Podcasts

Meet the Bloggers

Archive

Tags

#McAfeeFOCUS, #MFETrivia, #SecChat, #SecurityLegos, $1 million guarantee, 3DS, 3G, 12 Scams of Christmas, 99 things, 419 scam, 2011 Threats Predictions, 2012, 2012 London Olympics, 2012 Security Predictions, 2012 Virtual Sales Kickoff, Abbreviation, access to live fraud resolution agents, Account Takeover Scams, Accredited Channel Engineer, ACE, ACE certification partner, Acquisition, addiction, Adobe, adult online content, advance-fee fraud, Advanced Persistent Threat, advanced persistent threats, adware, AET, affiliate marketing schemes, Alex Merton-McCann, Alex Thurber, AMTSO, analysis, Android, Android/FakeToken, Android/FakeUpdates, Android/NickiSpy, android antivirus, Android Bot analysis, Android Dropper, Android Exploit, Android Malware, Android Malware Analysis, Android Market, Android Mobile Malware, Android Rooting Exploit, Android security, android security app, Android SMS broadcast, animation, Annual Partner Survey, Anonymous, Anonymous Group, anti-malware, anti-phishing, anti-spam, anti-spyware, anti-theft, anti-virus, anti-virus program pops up, Antievasion, antivirus, Antivirus software, APIs, App Alert, Apple, application blacklisting, application developers, applications, application security, app protection, apps, app safety, app security, APT, Arun Sabapathy, ASIC, ATM scams, ATM skimming, attack, attacks, Australia, authentication, automobile, automotive, AutoRun malware, AV-TEST.org, award, awards, Backdoor, Back To School, Bad Apps, balanced scorecard, bank accounts, bank fraud, banking, banking fraud, Belarus, Bernie Madoff, best practices, beyond the PC, Big Data, big security data, bill collectors call for nonpayment, Bin Laden Scams, Biological Computer, Bitcoin, BlackBerry, Blackhat, Black Hat, black hat hackers, blue screen, Bluetooth, book, bot, botnet, botnets, bots, Brazil, breach, Brent Sanders, bueno, buffer overflow, Business IT, C-SAVE program, Cameron Diaz, canada online scams, CanSecWest, car hacking, case study, celebrities, certification, chain mails, Change Control, channel partner, Channel Partners, Channel Partner Town Hall, Channel Program, Channels Town Hall, Charity Phishing Scams, child identity theft, children online safety, children safety online, child safety, Chile, China, chris barton, christmas, Christmas scams, christmas shopping, Christmas shopping concerns, Christmas shopping crimes, chromebook, CIO Insomnia Project, CISO Executive Summit, Citrix, Civil War, class action lawsuit, clickjacking, cloud, cloud apps, Cloud city, Cloud computing, Cloud Expo, cloud security, Cofer Black, collaboration, college students, Commercial/SMB, Commercial and Enterprise Deal Registration, Compliance, computer, computer issues, computers, computer security, computer support, conference, Conficker, consolidation, Consumer, consumerization, consumerization of IT, consumer threat alert, consumer threats, Consumer Threats Alert, Content Protection, Continuing Education, cookies, Corporate Responsibility, counter identity theft, creating safe passwords, creating strong passwords, credit card fraud, credit card fraud and protection, credit card skimming, credit card thefts, credit fraud alerts, credit monitoring, credit monitoring and resolution, credit scores, crimeware, critical infrastructure, cross-site scripting, CSP, currency, customer service, CVE-2012-0158, Cyber, cyber addiction, cyber attack, cyberattacks, cyberbullying, cyber bullying, cybercrime, Cybercrime, cybercriminal, cyber criminals, cybercriminals, cybercrooks, cyberespionage, cyber ethics, Cyber Insurance, Cyber Intelligence Sharing and Protection Act of 2011, cybermom, Cyber Monday shopping, cybermum, cyber mum, Cybermum India, Cyber risks, cybersafe, cybersafety, cyber safety for women, Cyber savvy mom, cyber scams, cyberscams and identity theft, cyber security, cybersecurity, cyber security awareness, cybersecurity concerns, cybersecurity mom, Cyber Security Mom, cybersquatter, cybersquatting, cyberterrorists, cyber threat, cyberthreats, cyberwar, dangerous searches, Darkshell, data, Database, database activity monitoring, database security, data breach, data breaches, Datacenter, data center, data center security, Data Classification, data loss, Data Loss Prevention, Data Protection, Data Protection Act, dating scams, Dave DeWalt, Dave Marcus, David Small, DDoS, Deal Registration, decade of cybercrime, deceptive online promotions, dedicated security appliances, Deep Command, DeepDefender, Deep Defender, Deepika Padukone, DeepSAFE, DefCon, DefCon Kids, denial of service, denied credit, Department of Commerce, device, Device Control, devices, dewalt, digital assets, digital assets worth, Digital Certificates, digital devices, digital gadgets, digital music and movie report, distributed denial of service, DLP, Dmitri Alperovitch, DoS, DougaLeaker, download, downloader, downloaders, drivers license, drivers license identity theft, dumpster diving, Duqu, e-card scams, e-gold, e-mail id, earnings, easter, Easter scam, eBay, ecards, ecard spam, eCommerce, Ecuador, education, Eelectric Vehicle, EFF, election, email, Email & Web Security, Email & Web Security, email accounts, Email Protection, email scam, email scams, email security, email spoofing, embedded, embedded devices, Embedded Security, EMEA, Emerging Markets, Emerging Market Security, EMM, employment fraud, Employment Identity Theft Scams, encryption, Endpoint Protection, Endpoint Security, Endpoint security suite upgrade, Enhanced Deal Registration, enterprise, enterprise mobility, enterprise resource planning, enterprise scurity, enterprise security, epayment, epo, ePO Deep Command, ePO DeepCommand, ePolicy Orchestrator, Epsilon, epsilon security breach, ERP, ESM, espionage, etiquette, EV, Exif, exploit, Exploit for Android, exploiting real brand names, exploits, facebook, Facebook Security, Facebook spam, Facial recongnition, fake-av, fake alert, fake ant, fake anti-virus software, Fake AntiVirus, fake anti virus, Fake Anti Virus Scams, fake emails, Fake Identity, fake software, fake system tool programs, fake updates, fake websites, false, families online, family, family identity safety, family online safety, family protection, Family Safety, Farmville, FBI, FDCC, fictitious identity theft, FIFA, file sharing, financial scams, Financial Security, Firesheep, firewall, FISMA, Fixed Function Devices, Flash, flashback, Focus, Focus11, FOCUS 2011, forrester, forwards, Foundstone, France, France Law, fraud, fraud resolution, fraud resolution agent assistance, fraudulent credit card or bank charges, free, freely downloadable morphing tool, free money scam, free money scams, free WiFi spots, french, French Law, Friday Security Highlights, FTC, games, gaming, gaming consoles, Garter, Gartner, Gartner Security and Risk Management Summit, Gavin Struthers, Gaza, George Kurtz, geotag, gift cards and iPad promotions online, gift online shopping, gift scams, Global Cybersecurity, Global Payments, Global Risk 2012 report, Global SecurityAlliance Partner Summit, global threat intelligence, gmail, gold software support, good parenting, google, google code, Google Play, government, GPS, gratis, GSM, GTI, hacker, Hackers, hackers steal credit card numbers and sensitive personal data, hacking, Hacking Exposed, Hacktivism, Hacktivity, harassment, HB1140, Healthcare, heidi klum, Here you have worm, Heuristics, Hi5, HIPAA, Hispanic, hoax, hoax - slayer, holiday gifts, holiday malware, Holidays, holiday scams, holiday screensavers, holiday shopping, holiday shopping fraud, holiday websites, home network issues, host intrusion prevention, Host IPS, household devices, how to set up wi fi, how to talk to kids, how to talk to teens, HV, Hybrid Vehicle, ICS, IDC, identify potential cyber-threats, identify spam, identity exposure, identity fraud, identity fraud scams, identity protection, identity protection $1 million guarantee, identity protection alerts, identity protection fraud, identity protection surveillance, identity surveillance, identity theft, identity theft celebrities, identity theft expert, identity theft fraud, identity theft protection, identity theft protection identity protection fraud, identity theft protection product, identity theft resolution, identity theft ring, identity theft risk, identity theft scams, identity theft tax scams, Identity thieves and cybercriminals, identity threat protection, IDF 2011, ID theft, iframe, IIM Bengaluru suicide case, illegal immigrants, impersonation, in.cgi, Incident Response, Incumbency Advantage Program, India, India cybermum, Indian kids, Indonesia, industrial control systems, infected mobile apps, information collected by advertisers or social media marketing, Information leak, Information Protection, Information Security, Information Warfare, Infrastructure, Initiative to Fight Cybercrime, innovation, insiders, Insider Threats, integration, Integrity, Integrity Control, intel, intellectual property, internet addiction, internet connected devices, Internet Explorer, Internet filtering, internet identity trading surveillance, Internet monitoring, Internet Phishing Scams, internet privacy, Internet Safety, internet security, internet security tips, internet time limits, Interop, in the cloud, IntruShield, intrusion prevention, In vehicle Infotainment, investment scams, iOS, IP, iPad, iPad scams, iphone, IPS, IPv6, IRCBOT for android, IRS, IRS scams, I Series, IT, IT as a Service, itouch, IT Security, IT Security market, Japan, japan earthquake malware, japan earthquake safe donation, japan earthquake scams, japan tsunami scams, java, JavaScript, job applications, Joe Sexton, John Bernard Campbell, julian Assange, kama sutra koobface, Katrina Kaif, keep family PC safe, Kernel 0day vulnerability, keycatchers, keyloggers, kids, kids online behavior, kids online safety, kids safety, king county, koobface, kurtz, labs, laptops, Larry Ponemon, LART, Late Payment Scam, law, law enforcement, LCEN, legal, legal identifier, legal risk, linkedin, Linux, Linux/Exploit:Looter Analysis, Linux and Windows, live-tweeting, live access to fraud resolution agents, lizamoon, Lloyds, Location services, Lockheed Martin, logging out of accounts, login details, LOIC, Looter Analysis, Lori Drew, loss of gadgets, lost, lost or stolen driver’s license credit cards debit card store cards, lost or stolen Social Security card or Social Security number, lost or stolen wallet, lost wallet protection, lottery, luckysploit, LulzSec, M&A, mac, mac/OSX, Mac antivirus, mac malware, Mac OSX, Mac OS X, Mac security, mac threat, mailbox raiding, Mail fraud, mail order bride spam, Malicious Android Application, malicious apps, malicious files, malicious program, Malicious QR Code, malicious sites, malicious software, malware, Malware Experience, malware forums, Malware research, malware threats, malweb, managed security services, Management, managing personal affairs online, map, mapping the mal web, maps, Marc Olesen, Mariposa, mass mailing worm, mass sql injection, mastercard, Maturity Model, mcaf.ee, McAfee, Mcafee's Who Broke the Internet, McAfee-Synovate study, mcafee all access, McAfee AntiSpyware, McAfee Antivirus Plus, McAfee Application Control, McAfee Channel, McAfee Channel Partner, McAfee Cloud Security Platform, McAfee Consumer Threat Alert, McAfee Data Loss Prevention, Mcafee DLP, McAfee Email Gateway 7.0, McAfee Employees, McAfee Enterprise Mobility Management, McAfee ePO, McAfee ePolicy Orchestrator, McAfee Facebook page, McAfee Family Protection, McAfee Family Protection for Android, McAfee Firewall Enterprise, McAfee FOCUS, McAfee FOCUS 2011, McAfee Identity Protection, mcafee identity theft protection, McAfee Initiative to Fight Cybercrime, McAfee Internet Security, McAfee Internet Security for Mac, mcafee internet security for mac; mcafee family protection for mac, McAfee Labs, McAfee Labs Q3 Threat Report, mcafee mobile, McAfee MobileSecurity, McAfee Mobile Security, McAfee MOVE AV, McAfee Network Security Platform, McAfee Network Threat Response, McAfee NSP, McAfee Partner, McAfee Partner Learning Center, McAfee Partner of the Year Award, McAfee Partner Program, McAfee Partner Summit, McAfee Policy Auditor, McAfee Q4 2011 Threat report, McAfee research, McAfee Rewards, McAfee Risk Advisor, McAfee Safe Eyes, McAfee Safe Eyes Mobile, McAfee Scan and Repair, McAfeeSECURE, McAfee SECURE, mcafee secure shopping, McAfee Security Journal, McAfee Security Management, McAfee security products, McAfee security software offer, McAfee Security Webinars, McAfee SiteAdvisor, McAfee Site advisor, mcafee spamcapella, McAfee TechMaster services, McAfee Threat Predictions, mcafee threat report, mcafee total protection, McAfee Vulnerability Manager, McAfee Vulnerability Manager for Databases, mcafee wavesecure, McAfee® Internet Security Suite, McCain, medical identify theft, Medical identity theft, medical records, michael jackson, Microsoft, Microsoft Security Bulletin, Mid-Market, Middle East, Mike Decesare, Mike Fey, MMORPG, Mobile, mobile antivirus, mobile app, mobile applications, mobile apps, mobile banking, mobile carriers, Mobile Commerce, mobile data communications, Mobile Data Protection, mobile data protocols, mobile device, mobile devices, mobile devices and security threats, mobile devices issues, mobile identity security, mobile malware, mobile phones, mobile phone spyware, mobile protection, mobile safety tips, mobile security, mobile security app, mobile security software, mobile smartphone security, mobile spam, mobiles security, mobile threats, mobile wireless internet security concerns, Moira, Moira Cronin, mom, money laundering, monitor a child’s identity, monitor credit and personal information, monitoring, Morphing, most dangerous celebrities, Mother's day, mothering, mothering advice, mothering boys, mothering Internet safety, Mother’s day spam, movies, MS12-020, M Series, msn spaces, multiple devices, multiple social security numbers, mum, Mummy blogger, myspace, MySQL, mystery shoppers, NACACS, national cybersecurity awareness month, National Cyber Security Awareness Week, national identification card, NCSA, ndr, near field communication, Netbook, netiquette, Network Evasions, Network Perimeter Security, Network Security, Network Security; Email & Web Security; Security-as-a-Service, network security server security, New teen survey, new year resolution, New York Times, next-gen IPS, Next Generation, next generation data center, Next Generation IPS, NFC, NickiSpy, Nigerian 419 Scam, nigerian scam, Night Dragon, NIST, Nitol, NitroSecurity, Nitro Security, NitroView, north america, North Korea, NotCompatible, Oak Ridge National Laboratory, obama, Occupy Wall Street, OCTO, OLE, olympics, Olympic scams, OMB, online, Online Backup, online banking, online banking safely, online book shopping, online bookstore, online child safety, online coupon scams, online credit fraud, online danger, online dangers, online dating, online e-tailers, online ethics, online fraud, online game, online games, online game spam, online gaming, online gangs, online harassment, online marketing sites, online personal data protection, online predators, online safety, online safety for kids, online safety of kids, online safety tips, online scams, online search, online security, online security education, online shopping, online shopping risks, online shopping scams, online shopping threats, online surfing, online threat, onlinethreats, online threats, online video, Open Source, operational risk, Operation Aurora, Operation Shady RAT, Optimized, Orange, organized crime, organized criminals, OS/X, oscars, outages, outlook, OWASP, P2P, PARC, parental advice, Parental control, parental controls, Partner Acceleration Resource Center, Partner Care, partners, Partner Summit, passport, password, password complexity check, passwords, password security, password stealer, Pastebin, patch, Patch Tuesday, Patmos, Paul Otellini, pay-per-install malware, Payload, payment, paypal, PC, PC Addiction, PCI, PCI Compliance, PCI DSS, PCs, pc security, PDF, pedro bueno, peer to peer, Peer to Peer file sharing, Pemberton, perception, personal identity fraud, personal identity theft, personal identity theft fraud, personal information, personal information loss, personal information over mobile phones, personal information protection, Personal information security, personal privacy, personal protection, peter king, Phantom websites, phishing, phishing kits, phishing scams, phishing shareware, pickpockets, pic sharing, piers morgan, PII, piracy, Playstation, policies, Ponemon Institute, Ponzi scam, pop ups, pornography, Postcode Lottery, posting inappropriate content, posting videos online, PostScript, potential employers, Potentially unwanted program, power grid, power loss, Pre-detection, Pre-Installed Malware, predictions, Premium SMS Trojan, president obama, Printers, privacy, Privacy Awareness Week, privacy setting, privacy settings, proactive identity protection, proactive identity surveillance, Products, promotion, Protect all devices, protect devices, protect digital assets, protection, protect teens, provide live access to fraud resolution agents, Public-Private partnerships, public policy, Public Sector, puget sound, Pune Police, pup, PWN2OWN, pws, qr code, QR codes, quarterly threat report, Ramnit, RAT, rdp, Rebecca Black, Records phone conversations, reference architecture, regulation, regulations, Renee James, reporting, reputational risk, Rep Weiner, research, resolutions, responsible mail, restore credit and personal identity, retail, RFID, ring tones, risk, Risk Advisor, risk and, Risk and Compliance, Risk Management, risk of personal information loss, risks of online shopping, risky, Riverbed, Robert Siciliano, roberts siciliano, rogue anti-virus software, rogue applications, Rogue Certificates, ROI, romance scams, Rookits, Rooting Exploit, rootkit, RootkitRemover, Rootkits, RSA, RSA 2010, RSA 2012, RTF, Russia, s, SaaS, SaaS Monthly Specialization, SaaS security solutions, safe, safe email tips, safe online shopping, safe password tips, Safe search, safe searching, Safe surf, safe surfing, safe transactions, SAIC, Saudi Arabia, Saviynt Access Manager, SCADA, scam, scammers, scams, SCAP, scareware, SchmooCon, schools, screensavers, sear, search, Search engine optimization, Search engine poisoning, SEC Guidance, SecTor, secure cloud computing, Secure Computing, secure container, secure devices, secure new devices, secure smartphone, secure wi fi, security, Security-as-a-Service, Security 101, Security and Defense Agenda, security attacks, security awareness, security breach, security breaches, security conferences, Security Connected, Security Connected Reference Architecture, Security Influence, security information and event management, security landscape, security management, security metrics, security optimization, security policy, Security Seals, security software, security threats, self-defence, sensitive data, sensitive documents, Sentrigo acquisition, seo abuse, settings, sexting, Shady RAT, SharePoint, shopping scams, shortened URLs, short url, SIA Partners, SIEM, simple safety tips, site advisor, SiteAdvisor, Situational Awareness, SlowLoris, Small Business, Smart Grid, smartphone, smartphones, smartphone safety, smartphone security, smart phone threats, SMB, SMB Advisor Tool, SMB Extravaganza, SMB Specialization, smishing, sms, SMS Lingo, sniffing tools, social business, social engineering, social media, social media online scams, social media passwords, social media threats, social network, social networking, social networking best practices, social networking scams, social networking sites, social networking sites security, social networks, social responsibility, Social Security, Social Security Card, social security number, Social Security number fraud, social security number theft, Social Security number thefts, software, Software-as-a-Service, solid state drive, Sony, South Korea, spam, spam mail, Spams, spear, Spearphishing, Spellstar, SpyEye, Spyware, sql attacks, SQL Injection, SSN fraud, st. patricks day, State of Security, stay safe from phishing, Stealth, stealth attack, stealth crimeware, stealth detection, Steve Jobs, Stinger, stolen cards, stolen mail, stolen medical card, stolen passwords, stolen Social Security number thefts, Stop.Think.Connect, storage, student loan applications, Stuxnet, subscription, Suites, summer activities, Summer holidays, summer vacation, Support, support services, surfing, suspicious messages, swine flu, Symbian, T-Mobile, Tablet, tablets, tablet security, targeted attacks, taxes, tax filing tips, taxpayer warning, Tax Preparer Scams, tax returns, tax scams, tax season reminder, TCO, teacher abuse over the internet, Tech Data, tech gifts, technical support, technology development, technology trends, teen hate video, teens, teens online dating, teens online safety, teens posting video, Telecommunications, Testing, text message, text messaging, The VARGuy, threat, threat reduction, Threats, threats on women's day, thurber, Tips, tips and tricks, tips to mobile security, TJX, Todd Gebhart, tools, Total Protrection 2012, TPM, traffic manager, travel related online scams, travel risk, travel security, trending topics, trojan, trojan banker, trojans, Trust and Safety, Trusted Computing Module, trustedsource, trusted websites and web merchants, Trustmark Security, tweens, tweet, Tweets, twitter, Twitter celebrities, Twitter online security, twitter spam; phishing; twitter scam, type in website address incorrectly, types of phishing, typing in incorrect URLs, typos, typosquatting, U.S. Cyber Challenge Camps, UAE, Ultrabook, unauthorized credit card transactions, Underground Economies, unique password, United Arab Emirates, unlimited technical support, unprotected PCs, unsecured unprotected wireless, unsecured unprotected wireless security risks, unsecured wireless, Unsecure websites, unsubscribe, UPS scam, UPS scams, urchin.js, URL hijacking, URL shortening services, USB drives, use of cookies advertising personal security, use of Social Security number (SSN) as national ID, US ESTA Fee Scam, US passport, US Visa Waiver Program scam, valentine scams, valentines day scams; romance scams; email spam, valentines day scams; romance scams; valentine threats, Vanity Fair, vbs, Vericept DLP, verify website's legitimacy, ViaForensics, video game, vinoo thomas, violent video games, Virtualization, VIrtual Machines, Virtual Sales Kickoff 2012, virus, Viruses, Virus protection, VirusScan Enterprise with ePO 8.8, visa, vista, VMworld 2011, Vontu DLP, vPro, vulnerability, vulnerability management, Vulnerability Manager, vulnerability manager for databases, waledac, WAN, water facility, water pumps hacked, water treatment facilities hacked, wave secure, web, Web 2.0, Webinar, web mobs, web protection, web searches, web security, Websense DSS, Web services, web sites, web threats, welfare fraud, wells fargo, what to do when your wallet is lost missing or stolen, white hat hackers, Whitelisting, Wi-Fi WEP WAP protection breach, wifi, Wii, wikileaks, windows, Windows 7, Windows Mobile, Wind River, work with victim restore identity, World Cup, world of warcraft, worm, Worms, wrong transaction scam emails, www.counteridentitytheft.com, Xbox, Xerox, xirtem, xmas, xss, youth, youtube, you tube videos, Zbot, Zero-Day, ZeroAccess, zeus, zombie, zombie computers, zombies, • Facebook etiquette, • Most dangerous celebrity, • Parental control

Desperate Measures?

Monday, May 7, 2007 at 5:40am by Archive
Archive

Recently Gartner slammed 3Com’s TippingPoint division for sponsoring zero day contests without giving the vendor Apple Inc. a chance to fix the flaws before their patch release. They apparently paid $10,000 bounty to Dino Dai Zovi, a well distinguished security researcher at the recent CanSecWest conference.

Wow! It is rather ironic that a security company, who presumably wants to protect customers, will first put everyone to risk, not notify the vendor on time, and then release signatures! The anti-virus community, long the target of (bogus) claims that they write viruses to make money, wouldn’t touch a contest like this with a barge-pole. In fact, even staunch full-disclosure advocates note the ethical disconnect implicit in security companies producing content earlier than their competitors via such initiatives (see http://blog.ncircle.com/archives/2005/08/3coms_zero_day_initiative_cest.html and our premier issue of Sage.)

As security vendors, our mission is to protect our customers and the internet community at-large , not to create hype and FUD by giving the world a chance to exploit unpatched flaws!! Failing to disclose to anyone leaves the good guys in the dark – but supporting irresponsible disclosure give the bad guys night vision…

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (8)

  • Rahul Kashyap May 14, 2007 10:26AM

    Hey Terri (and others),

    Thanks for your elaborate reply. As you mentioned, yes I can also see that your stance on such bounty programs has changed :) . Security Research is definitely *capable* of befitting everyone as long as people behave responsibly and ethically. There’s no doubt about that. What we’re discussing here is about the ethics aspect and NOT about security research.

    As I have previously mentioned, Stuart states in his Sage article an example of a malicious hacker who had brought down a website (http://www.techworld.com/security/news/index.cfm?NewsID=3465 ) and someone with the same alias ATmaCA was credited with finding a new vulnerability in your own ZDI program (http://www.zerodayinitiative.com/advisories/ZDI-06-015.html ). Is this the same person? Possibly, and we do not know what *other* damage he/she might have done, now that he/she is well funded! This lack of accountability is what is really *BAD*.

    Exploits are like digital weapons, and vulnerabilities are the raw materials. People who run bounty and compensation programs are the equivalent of arms dealers with ineffective laws and no oversight. There is absolutely no way of guaranteeing that bounty programs do not go astray in the confusion or are misused. These programs are tantamount to funding weapons creation in the digital age and the people running the programs have no accountability. Yet, when something goes astray with an exploit generated from their disclosed vulnerability or researcher, they have no risk from benefiting from the press and exposure.

    Secondly, you mentioned that “Dino (and every ZDI researcher out there) would disagree with being called malicious.” I think that it is unfair for you to drag Dino into this because, if you scroll up, I’ve explicitly mentioned that we are NOT against security research. In fact McAfee Avert Labs has some of the top notch security researchers in the industry and no one can doubt that fact. What we need to note here is that as the funding party of this event, can you guarantee that the next time you allow this, no POC or exploit gets leaked in the next conference? The point here is again responsibility and ethics, that’s exactly what Gartner is saying here again [ http://www.gartner.com/DisplayDocument?id=504693&ref=g_sitelink&ref=g_SiteLink ]

    We’re here in the security industry to make things better and not to fund activities that are irresponsible and gives us a ‘coolness’ factor buzz in the media.

  • xrt-27 May 11, 2007 2:46PM

    …as a simple end-user/administrator and NOT a security researcher,I ‘m probably not the most qualified person in the world for commenting this out.
    So,excuse me if I seem kind of “intruding” here,but I’m pretty sure that since my thoughts are also shared by a wide area of customers,they also have their value…

    Amongst various articles responding to McAfee’s statements for ZDI,
    the responce that mainly attracted my interest was this one…
    http://blog.ncircle.com/blogs/vert/archives/2007/05/why_zdi_benefits_everybody.html
    So,allow me to copy/paste a few words from there and comment on them…

    “They referenced a two year old post by a former employee and attempted to use it as ammunition in their obvious attack on Tipping Point.
    I find it most interesting that their attack has so little basis that the only ammunition they could find came from a two year old post… The security industry is constantly growing and changing… It’s changing so fast that I would consider a post from 6 months ago to be too old to act as a reliable reference.”

    I guess that THEIR way of referencing “former-employees”‘ statements,
    is also giving away some food for thought…
    6 months,2 years,20 years or whatever…now,I really don’t get this one:
    since when ethics became…time-dependent?
    Maybe since time became…equal to money?

    And later,in the same article:
    “Enter ZDI and iDefense. Now you have a third option, you sell the vulnerability you discover to one of these companies and suddenly everyone benefits. You walk away with some cash in your pocket, the vendor deals with a company that believes in responsible disclosure and the purchaser of the vulnerability has new value-add for it’s customers. “Yes we’ll identify this vulnerability that the vendor isn’t even aware of yet.” Everyone wins.”

    …Enter ZDI and iDefense…Now you have a third option…
    You walk away with some cash in your pocket…Everyone wins…tic-toc,tic-toc…when you wake up,you’ll remember nothing…Enter the Dark Side…the Matrix has you… ;-)

  • Kurt May 9, 2007 12:02PM

    So Rahul- is this your organization idea of responsible?
    http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=528

    “VIII. DISCLOSURE TIMELINE
    08/14/2006 Initial vendor notification
    10/17/2006 Second vendor notification
    02/07/2007 Third vendor notification
    02/08/2007 Initial vendor response
    05/08/2007 Coordinated public disclosure

    6 months to even RESPOND to reported vulnerability in your product??? What do you say for that? Maybe McAfee should stop criticize other competitors and start working on their own policy!

  • Richard May 8, 2007 6:30AM

    Rahul,

    I think you’re confusing CanSecWest announcing a winner to the Hack a Mac contest with ZDI releasing details of the vulnerability. It’s not the same thing, and as far as I saw reported, only ZDI, the matasano researcher, and Apple ever had access to the 0day details and exploit. The fact that Apple thanked them all in their advisory should be clue enough.

    With regard to your company’s stance on paying for vulns, I think Mike Rothman said it best::

    “…there is very little incentive for security researchers to do their job. They are all finding these bugs in their free time. Sure it helps notoriety and is basically a marketing expense, but this isn’t how they pay the bills. So putting a little bounty is place isn’t a bad thing. Remember, there is a huge community of security researchers out there called the bad guys. They are finding holes and breaking things ALL THE TIME. We need to find ways to allow folks on the right side of the battle to do what they do, and make some money. That’s good for all of us. “

    I think in general, the industry has warmed to the idea of paying researchers (with the exception of tipping point’s competitors – including mcafee).

    Richard

  • Terri May 7, 2007 10:43PM

    Rahul,
    While I respect your opinon and assertions, and in fact used to share those opinions at one time, I think you are misunderstanding a primary point-
    You say:
    “Isn’t that unfair to give absolutely no notice to a vendor to patch?? How would you feel as a vendor if you were told that a new vulnerability has been disclosed and news has already started floating out in the public? Given that now the timelines for creating exploits for vulnerabilities is becoming shorter and shorter, you’re effectively putting everyone using QuickTime (in this specific case) at risk. “

    What I think you are missing here is that Apple *was* given the time to patch. When Dino found the vulnerability, he sold it to the ZDI and did NOT disclose it to anyone else. We turned over the vulnerability to Apple within 30 minutes of contracting it. We did_NOT_Disclose the details of the vulnerability to the public. Apple spent a week getting a patch ready, and when they released a patch we released an advisory.

    Media inquiries about the fact that a vulnerability existed vs. customers being at risk are not the same thing. If the press heard that the sky was falling, and asked me to comment, and I said “Yes, the sky is falling soon…” that doesn’t mean that the sky has fallen, or that you now know how it will happen.

    Purchasing the vulnerability from the contest that was already taking place was no different than any other vulnerability that the Zero Day Initiative handles- except for the fact that it was, afterall, a contest- and reporters were on site to write stories about whomever won.

    Had I specifically given them details about the vulnerability, how to use it, and maybe a little example of how to reproduce it… I would be happy to have you call foul. Since that was NOT the case, it’s incorrect for you to claim it was.

    If you have a problem with the practice of purchasing vulnerabilities, that’s ok, and I respect (and used to) share your opinion- but please do not make false statements regarding responsible disclosure- when the details of this vulnerability were- in fact- disclosed responsibly to Apple on the same day(hour) we purchased it.

    Regarding this excerpt you quoted:
    “But if payment programs simply fill the coffers of malicious hackers who look hard for more and more vulnerabilities, then vendors, customers, and legitimate researchers are all hurt.
    In the first case, vulnerability disclosure means everyone wins; but in the second case, we all lose.”

    I think Dino (and every ZDI researcher out there) would disagree with being called malicious. Did you know, that the majority of security researchers I’ve met are not malicious? In fact, I worked in Microsoft’s Security Resonse Center directly dealing with researchers and fixing vulns for many years- and what always suprised me the most is that I never actually *met* any criminals.

    Well, almost true… I did meet Kevin Mitnick one time at BlackHat, but he’s not a *real* security researcher and doesn’t actually count.

    What I do grow tired of is the idea and constant misassertion that researchers are criminals. The criminals don’t sell their vulns to ZDI- they are too busy using them to make amounts of money that we could never keep up with. Additonally, criminals don’t seem to show up at conferences and give away their 0day just to win a Mac. They are busy automating the process of taking other peoples vulns and exploits and turning it into cash for information warfare, industrial espionage, nation/state hostilities.

    In the world of vulns, there are a lot of people to be afraid of- but those folks aren’t generally running around conferences hacking mac’s and they probably aren’t selling to ZDI.

    And did you know, that we do not redistribute vuln information to any sort of paid subscribers as the report you cite claims? Not even our own IPS customers get information about the vulns we buy until AFTER the vendor patches them. Until the vendor releases a patch themselves, all our customers know is that they have a filter for a Zero Day vulnerability. That’s it.

  • Rahul Kashyap May 7, 2007 7:12PM

    Hey Terri, et al

    It’s a very simple, basic rule that we follow as a security vendor that I want to point out in this blog (no homework required on this) Rule #1 – Protect (the customer and the internet community at large)

    We all appreciate vulnerability research in general, we’ve never said anything against that (In fact we acknowledge security researchers in the sage article that I had earlier pointed out). But the question here is about ethics. Why would a security vendor want to sponsor an activity that can potentially put users to risk before a patch has been out? As you said, “(vuln disclosed 30 minutes to Apple after officially buying it from Dino).”

    Isn’t that unfair to give absolutely no notice to a vendor to patch?? How would you feel as a vendor if you were told that a new vulnerability has been disclosed and news has already started floating out in the public? Given that now the timelines for creating exploits for vulnerabilities is becoming shorter and shorter, you’re effectively putting everyone using QuickTime (in this specific case) at risk.

    About McAfee’s stance on vuln disclosures, you can find it here: http://www.mcafee.com/us/threat_center/report_vulnerability.html

    As regards the ZDI model, we’ve already discussed this in our sage article (by Stuart McClure) that I had initially pointed out. [http://www.mcafee.com/us/local_content/white_papers/threat_center/mcafee_sage_v11_en.pdf ] Let me give you some excerpts from this (in case you haven’t read it):

    “…If companies provide a cash reward for bugs found in their own software, that’s a good thing. After all, if a researcher has invested his or her time finding a bug, it’s fitting for the benefiting vendor to pay for the work.
    But when security companies pay for finding bugs in other vendors’ software, the results may not be so beneficent.
    By using the research of others to publicize vulnerabilities, for example, these companies may sell more subscriptions to their threat intelligence services and gain publicity from it—in other words, they will make money”

    “…From the customer’s perspective, the disadvantages of such a vulnerability discovery program are many. The more vulnerabilities that are found, the more you must fix to protect yourself; and the more you must fix, the fewer you inevitably will. Further, the more people involved with a particular finding, the more likely that information about the vulnerability will leak out. And a leak means that someone can build a worm that will affect customers before they are patched or prepared. The last point strongly undermines the expressed goal of the program: to protect people.”

    “…If an organization offers payment to motivate individuals to report their findings and uses that information to improve its own products, then who can blame them? Or if a vendor discovers vulnerabilities as part of its everyday fight against threats and wants to incent its team members to report their findings, then such a program benefits everyone. But if payment programs simply fill the coffers of malicious hackers who look hard for more and more vulnerabilities, then vendors, customers, and legitimate researchers are all hurt.
    In the first case, vulnerability disclosure means everyone wins; but in the second case, we all lose.”

  • Terri May 7, 2007 12:47PM

    For your reference, the actual facts of the entire matter can be found here:

    ZDI advisory is here with timeline of disclosure events (vuln disclosed 30 minutes to Apple after officially buying it from Dino).
    ZDI disclosure policy here.
    Final thoughts and rebuttals on the hacking contest in our blog posting here.

    In order to help protect a larger customer base than our own, we also share ZDI information free of charge to any IPS competitor that asks for it, with minimal fine print.

  • c0uchw4rrior May 7, 2007 10:32AM

    Um, ZDI _did_ give provide Apple with the vuln details and did give them a chance to fix these flaws before their _coordinated_ disclosure. In fact, Apple’s updated QuickTime packages hit their update servers at the same time ZDI disclosed the vulnerability.

    Please get your facts straight.