NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
Home / News / Microsoft / Patches and Vulnerabilities

Patches and Vulnerabilities


Microsoft Will Buy Nothing from the Windows Vista Vulnerabilities Bazaar

The Redmond company will not get involved in a marketplace with vulnerabilities citing blackmail

By Marius Oiaga, Technology News Editor

10th of July 2007, 13:21 GMT

Adjust text size:


Security
Enlarge picture
Microsoft will have nothing to do with any form of online vulnerabilities bazaar. This is true not only for security flaws affecting the company's latest operating system but all its products. The reason why Microsoft will not get involved into the commerce with security vulnerabilities is because it finds an equivalence between a zero-day marketplace and up front blackmail. In this context, Roger Halbheer, Chief Security Advisor Microsoft EMEA, criticized
harshly the WabiSabiLabi vulnerabilities auctioning website, revealing that the initiative is nothing more than another example of irresponsible disclosure.

"Every vendor has to have transparent and clear processes to handle vulnerabilities. These processes ensure that there will be a timely reaction on responsible disclosed as well as on irresponsible disclosed vulnerabilities causing so called zero-days. These zero-days pose a major risk to all the computer users on the Internet. One could agree now, that not the zero-day is the problem but the vulnerability itself," Halbheer stated.

WabiSabiLabi's position is quite different. It states that the ethical disclosure system was abused and is not a viable business model. WabiSabiLabi aims to see security researchers get paid for the zero-day vulnerabilities they find. "The system introduced by "ethical disclosure" has been historically abused by both vendors and security providers in order to exploit the work of security researcher's for free. This happens only in the IT security field as for example, nobody in the pharmaceutical industry is blackmailing researchers (or the companies that are financing the research), to force them to release the results for free under an ethical disclosure policy," reads an excerpt from the WabiSabiLabi website.

WabiSabiLabi has an entirely different perspective over the issue of selling zero-days. What Microsoft calls an attempt to blackmail software vendors, WabiSabiLabi calls bringing "the world closer to zero risk." Microsoft fails to see eye to eye on this matter and stick to its old strategy. "Our policy here is crystal clear. We do not buy vulnerabilities. We acknowledge the finder in the bulletin. Additionally we bring them together with our Executives and developers at a conference called "Bluehat"," Halbheer added.

TAGS:

Microsoft | vulnerability | zero-day


Rating:
Fair (2.5/5) 7 vote(s) so far    

Read by 616 user(s) | Add comment | Link to this article
Subscribe to news | Print article | Send to friend

© Copyright 2001-2008 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Windows Vista Security Updates Infested with Malware

Do We Really Need Another Attack Vector (Safari) in the Windows Jungle?

Windows Vista - Wide Open to Attacks

Internet Explorer Is in a Lamentable Condition

Download June 2007 Microsoft Security Releases ISO Image for Windows Vista

Where Microsoft Patches Go, Exploits and Attacks Soon Follow

Recount: Windows Still Safest, Tops Mac OS X, Linux and Sun Solaris

Forget about Linux and Mac OS X - Windows Vista the Most Secure Operating System

Vista Is Top Dog

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 






SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM