* The right way and the wrong way to react to bad security news
Here’s a scenario to consider.
You’ve installed a new system – say, a new ectopic frizzilator for the gandromorphic exilitory network. You’ve configured it according to specifications and have opened it for full access by your users.
Two days after the system opens for business, a couple of users show up at your office with some bad news: they have discovered that anyone can launch a denial-of-service attack on the frizzilators simply by pinging them. Turns out they were curious to know if the frizzilators responded to a ping, and sure enough, they did. Then, just to be thorough, they tried bombarding the frizzilators with pings and established that the devices went completely dead, preventing any exilitory activity at all during the ping-storm.
So how do you respond?
Do you
(a) Thank your users warmly for letting you know about the vulnerability, promise to keep them in the loop with news, and then get to work fixing it? Or
(b) Accuse them of hacking your systems and threaten to have them fired and even arrested?
Believe me, I have received e-mail from users in the (b) situation and know students who have suffered the same treatment for pointing out security flaws.
Why would anyone react to helpful employees or students who go to the trouble of pointing out a security vulnerability by attacking them? Remember, I’m not talking about any kind of intrusive or damaging testing here: a ping is a normal function on any network, not a hacking tool.
I think that the (b) response is an entirely irrational, emotional reaction of fear. The people reacting this way are afraid that they will be blamed for having a security hole; instead of being grateful for having the vulnerability pointed out, they convert their fear of punishment into anger at those who have put them in the uncomfortable position of having to admit and then correct what they think of as their mistake.
But everyone makes mistakes, especially when configuring gandromorphic exilitory networks. These are complex systems, and no one should expect instant perfection. What one _should_ expect is rapid response to newly identified problems; that’s part of a sound continuous-process-improvement strategy.
In my Master of Science in Information Assurance program at Norwich University, I established a rule from the very first that sometimes surprises students: any student criticizing any aspect of the program and providing a constructive solution we can use gets extra points. One of our students wrote to me saying that when she told her co-workers about getting an extra point on an exam for challenging a question and answer, they looked at her in disbelief; one said that challenging an exam question in _his_ graduate program would generate permanent dirty looks from the instructor for the rest of the course.
The other aspect of response (b) above may be a bad management environment. If people are punished for routine, fixable errors, it’s natural that they may pass on their mistreatment to others. If you have that kind of management environment, maybe you should take a look at my lectures on management style.
Try downloading my 13M-byte WinZIP file from:
Then run the PowerPoint file in it with the sound on for the narration. You may be able to spread the ideas around your office and change the climate of fear over the long run.
Let’s hope we can stop shooting the messengers.




