Bug reporting proposal lacks bite

Opinion
Jun 16, 20033 mins

A couple of weeks ago the Organization for Internet Security released a proposed standard for bug reporting, called the Security Vulnerability Reporting and Response Process.

OIS could more properly be called the Committee for the Defense of Buggy Software Vendors. Just check the membership roles – @stake, BindView, Caldera International (The SCO Group), Foundstone, Guardent, ISS, Microsoft, Network Associates, Oracle, SGI and Symantec. Imagine that, Bill Gates and Larry Ellison joining forces to protect the Internet – best check the weather report for Hades.

Setting aside for the moment the question of how anyone could enforce a policy on security breach reporting, let’s just examine the proposal on its merits.

The proposal outlines five steps:

  1. Discovery – Someone (called the Finder) discovers what they consider to be a security vulnerability.

  2. Notification – The Finder notifies the software vendor and advises it of the potential vulnerability. The vendor confirms that it has received the notification.

  3. Investigation – The vendor attempts to verify and validate the Finder’s claims, working collaboratively with the Finder.

  4. Resolution – If the potential vulnerability is confirmed, the vendor identifies where the flaw resides and then develops a remedy that eliminates or reduces the risk of the vulnerability.

  5. Release – In a coordinated fashion, the vendor and the Finder publicly release information about the vulnerability, along with its resolution.

Read the report  and notice how much space is devoted to form and protocol and how little to keeping networks safe.

Notice that the public, the people who are vulnerable to the security flaw, are not to be told about it until a patch has been developed. No patch, no public notice – but the security hole is still there, just waiting to be exploited.

Microsoft, and most of the members of the group, have had public relations disasters on one or more occasions when mishandling or ignoring security problems with their software. OIS is a propaganda mill designed to keep you from complaining about the lack of security in enterprise software by giving you a false sense of security. It doesn’t want to help you quickly plug security holes but, rather, it would like to hide the hole until it can develop an appropriate response.

I don’t like that. I want to know about the vulnerability – even if there isn’t yet a patch. Knowing the vulnerability, I can work around the problem until it’s fixed. Not knowing leaves my network open for exploitation.

Tip of the week

With all the problems plaguing the travel industry, Netpro has decided to move its fall version of the Directory Experts Conference for Active Directory from Barcelona to Ottawa this September. That’s a big plus for those in eastern North America even if Ottawa is not quite the cultural center Barcelona is. More time to concentrate on the seminars, I’d guess!