Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Details of Sybase ASE bugs withheld |
|---|---|
| Date: | Wed, 23 Mar 2005 12:54:36 -0500 (EST) |
<IMHONSFME - In My Humble Opinion Not Speaking For My Employer mode on>
In the broader context, I believe that Simple Nomad is exactly right: it will be bad for us and for everyone who uses such commercial products if security research firms are effectively gagged by legal threats, because we will less and less know what vulnerabilities exist in the products we use, until such time as we suffer an actual exploit against them.
</IMHONSFME - In My Humble Opinion Not Speaking For My Employer mode off>
-Jay Libove, CISSP
On Tuesday 22 March 2005 14:53, Marchand, Tom wrote:And what happens when the vendor won't indemnify the researchers? No more security bulletins? Wouldn't the vendors love that. Or would security researchers become outlaws?
It gets worse if you consider that the researcher may be researching a COTS product on behalf of a client who wants the software evaluated before it is implemented/purchased. Now where does the EULA lie? Company X bought the software, but pays me to evaluate it in a cubicle on Company X's property. Does the EULA apply to me? What if Company X already installed it on a computer, and *they* clicked "I Agree" during the license question and I am just there to rip things apart bit by bit?
This is why EULAs don't work in this context.
Additionally, myself and/or NMRC has been threatened with legal action from several companies or have done "legalish" things to try to scare us ("please GPG sign NMRC's disclosure policy with *your personal* GPG key and email it to us before releasing your advisory we don't want published"). My experience through my employer BindView also leads me to believe that given the chance any and all vendors will do anything to prevent public disclosure of bugs.
<tinfoilhat> IMO, several large vendors are waiting for one of the smaller companies to risk the bad publicity of going after a security researcher (criminal, civil, or both) so a precedence has been set. Assuming the courts decide in favor of the company instead of the researcher, security research as we know it will end as all the vendors come after us like biblical locust swarms, and we will go back underground, old school style. </tinfoilhat>
-- # Simple Nomad -- thegnome@nmrc.org # # C1B1 E749 25DF 867C 36D4 1E14 247A A4BD 6838 F11D # # http://www.nmrc.org/~thegnome/ #
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [VulnWatch] Details of Sybase ASE bugs withheld, Simple Nomad |
|---|---|
| Next by Date: | RE: Details of Sybase ASE bugs withheld, Evans, Arian |
| Previous by Thread: | Re: [VulnWatch] Details of Sybase ASE bugs withheld, Simple Nomad |
| Next by Thread: | iDEFENSE Security Advisory 03.21.05: Mac OS X CF_CHARSET_PATH Buffer Overflow Vulnerability, iDefense Customer Service |
| Indexes: | [Date] [Thread] [Top] [All Lists] |