Security Researchers Target Software Vendors with "Secure" Claims
As the moderator of the Bugtraq security mailing list for the past four years, Dave Ahmad has seen vendors making claims of security, only to be debunked by security researchers. Ahmad, based in Calgary, Canada, warns software vendors against making such statements, as they attract the attention of security researchers looking to find vulnerabilities. Recent examples include Mozilla Firefox and Apple's OS X, both touted as secure alternatives to mainstream software but found to have vulnerabilities.
Key Takeaways:
- Software vendors making claims of security attract the attention of security researchers, who are eager to find vulnerabilities and debunk the claims.
- Recent examples include Mozilla Firefox and Apple's OS X, which were touted as secure alternatives but found to have vulnerabilities.
- Vendors are more responsive to security concerns, with Microsoft and the open source community improving their security practices.
- The open source community has been pressured by high-profile researchers to improve their security practices.
- Security companies are selling their vulnerability data, keeping their findings private and charging a subscription fee.
- Technical methods for manipulating memory "heap" on several operating systems were widely published, leading to an onslaught of heap-related vulnerabilities being disclosed.
Statistics:
- 4 years: duration of Dave Ahmad as the moderator of the Bugtraq security mailing list.
- 18 years old: age at which Ahmad joined SecurityFocus to maintain the company's vulnerability database.
- 2001: year in which Ahmad took over Bugtraq.
- 2002: year in which SecurityFocus was acquired by security software maker Symantec.
- 95%: estimated percentage of good vulnerability researchers who have stopped disclosing their findings.
- $: the value of vulnerabilities being sold by security companies, leading to a motivation to keep them private.
Sources:
- Symantec
- Bugtraq security mailing list
- SecurityFocus
- CanSecWest security conference
- Phrack hacker magazine
- eEye digital security
- Microsoft
- Mozilla
- Apple
- Oracle