Vulnerability Value
The vulnerability has become a valuable commodity. Recently, it is rumored that the WMF vulnerability (0-day attack) was launched without the knowledge of the public. The vulnerability information was sold to $4000, although this is only a rumor that has not been confirmed yet. If this is true, I bet it is unprecedented, and I can be sure that it will not come later. Even companies like iDefense and 3Com are willing to buy undisclosed vulnerability information from these security researchers. How do you think these situations affect vulnerability research? No matter how you look at this issue, today, vulnerabilities are money.
Although programs provided by iDefense and 3Com cannot attract companies with security research groups, they can indeed influence independent researchers. With these procedures, independent researchers can devote themselves to this study. If he is good at finding vulnerabilities, he will be able to take this profession, and this research will become a full-time job. I think this is terrible.
Vulnerability Ethics
Some may doubt the ethics behind the vulnerability information. Security researchers should not reveal the vulnerability information without conscience, should they? Maybe so. Isn't that true? Should we expect security researchers to review whether commercial software is commercially available or free? If we think that sales of vulnerability information is against ethical standards, what should I first ask is the ethics of software that is very insecure and insecure? Of course, we know that developing software that has no vulnerabilities is impossible. Obviously, those companies should not stick their brains to develop security products. In this way, moral issues will not be entangled with the company, it only focuses on the bottom line of the problem. Developing security products requires time and money. Software companies do not like to spend time and money to solve these problems unless there is a fierce collision on this bottom line.
Which side will you stand on? Do you believe that a vulnerability becomes a real threat only after it is published? I believe that no matter whether it is public or not, it will pose a threat?
Why do we need to publicly expose vulnerabilities responsibly?
As for myself, I believe that these vulnerabilities will pose a real threat to us long before they are publicly exposed. These vulnerabilities were publicly exposed and pushed to the teeth of the public. After a long time, the software developers noticed the issue. After several months or even years, they did not make any public statements, it seems that they don't even know about it, but they are only looking for profit. This may seem like a software developer's attempt or a poor remedy for this insecure software transfer responsibility. The bottom line is that after a vulnerability is discovered and reported to a software dealer, the system is still vulnerable to attacks no matter whether or not the message is published.
Here, I have clarified that it is reasonable to report a vulnerability attack to the developer before reporting it to the Bugtraq. I have never said that this will not put the public in danger. It takes time to fix these problems, and I will not underestimate the difficulty of making patches for widely spread commercial software. However, there are some limitations here, that is, the developer's practice of escaping from reality and the rejection of known vulnerabilities will not be helpful to anyone.
I think it is time for developers to acknowledge these issues before releasing patches, especially those patches that have been taking them for several months or that have not been completed for more than a year. At least they should acknowledge the existence of the problem and provide some protection measures for people.
Finally, I believe those security researchers have helped us a lot. They should be rewarded. Although it is very important to publish vulnerability information responsibly, the response time is also a limiting factor for a responsible seller, because the public has been in danger long before the vulnerability is exposed. Finally, I want to talk about security researchers who have discovered these vulnerabilities, not who have made them.
Author profile:
Jason Miller manages the SecurityFocus IDS email list. He is also a threat analysis expert at semen Ike.