NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Microsoft Has No Plans to Enter the Vulnerabilities Market

The company policy involves only crediting vulnerability finders

By Marius Oiaga, Technology News Editor

22nd of February 2007, 08:14 GMT

Adjust text size:


Following announcements from various sources related to financial transactions involving vulnerabilities in Microsoft's software products, I asked Stephen Toulouse, senior program manager
for the Trustworthy Computing Group what were Microsoft's plans in this aspect.

The most illustrative examples of late are those provided by Trend Micro's chief technology officer, Raimund and by VeriSign's iDefense Labs. Genes revealed that on the black market, a critical zero-day vulnerability in Windows Vista goes as high as $50,000.

And VeriSign's iDefense Labs has announced the Quarterly Vulnerability Challenge, offering from $8,000 to $12,000 for vulnerabilities in Windows Vista and Internet Explorer 7 together with functional exploit code. In this context, I asked Toulouse for Microsoft's official position in relation to the commerce with vulnerabilities affecting its products.

"We're certainly aware of companies offering compensation for information regarding security vulnerabilities. Microsoft does not offer compensation for information regarding security vulnerabilities and does not encourage that practice. Our policy is to credit security researchers who report vulnerabilities to us in a responsible manner," Toulouse explained.

Of course that, since the moment was opportune, I also asked Toulouse if Microsoft is considering becoming a player on the market that trades vulnerabilities to its products. But Toulouse denied any possibility of a Windows Vulnerabilities Marketplace initiative.

"As I mentioned, Microsoft does not offer compensation for information regarding security vulnerabilities. Our policy is to credit finders who report vulnerabilities to us in a responsible manner. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests, by helping to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities with no exposure to malicious attackers while the update is being developed," he added.
Read by 690 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.1/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Patches Critical Vulnerability In Windows Vista

The Windows Vista MessageBox Vulnerability Goes Unpatched

Windows Vista UAC Implementation Vulnerability

Vista Windows.old

Windows Vista Remote Execution Vulnerability

Microsoft's Insecure Security - the Door for New Exploits

Internet Explorer 7 - Scarred By Vulnerabilities

Is Microsoft Sending the Right Signals for XP Users with Vista?

Vista vs. XP - Feature Comparison

Windows Vista System Restore

The $500 Million Windows Vista "Wow"

Why Won't Microsoft Declare Windows XP Expired?

KMS Crack for Vista Home Basic and Home Premium

Windows Vista - a Sterile Operating System

It's Raining Word Vulnerabilities

The MessageBox Vulnerability to Rain on Vista's Parade

Windows Ultimate Extra DreamScene Available

Kaspersky Reveals the Fundamental Vulnerability of Vista PatchGuard

New Windows Vista 3 Ways Crack

Workaround Available for Clean Vista Installations Via Upgrade Keys

Windows Vista Security Model - A Big Joke

Windows Vista Search Kills Google Search

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM