Vulnerability Disclosure: The Strange Case of Bret McDanel
نویسنده
چکیده
Responsible developers work hard to produce secure, reliable, and efficient software packages. No company wants its integrity compromised by hackers, employees, or legitimate users. Negative publicity damages a firm’s reputation. Legal proceedings can cost an organization millions and destroy any chance of long-term success. Realistically, few products are released without security flaws. Programmers and system designers strive to find security bugs during the development cycle or at worse during beta testing, when bugs can be fixed easily. Careful testing will allow internal programmers to debug the software without publicity or industry notice. The outcome may differ if outsiders discover a security breach. Malicious hackers may exploit the breach to obtain classified information, to destroy the integrity of the information, or simply for the challenge. Even self-described “ethical hackers” may share this information with no discretion. Given the speed of the Internet, security breaches can be transmitted worldwide in hours. This article deals with vulnerability disclosure, where the details of a security breach are freely available. It also deals with the bizarre case of Bret McDanel, a young computer expert who spent 16 months in federal prison after he exposed a security breach in his former employer’s software package.
منابع مشابه
Emerging Issues in Responsible Vulnerability Disclosure
Security vulnerability in software is the primary reason for security breaches, and an important challenge for IT professionals is how to manage the disclosure of vulnerability information. The IT security community has proposed several disclosure policies, such as full vendor, immediate public and hybrid, and has debated which of these should be adopted by coordinating agencies such as CERT. O...
متن کاملStrange quark matter attached to string cloud in general scalar tensor theory of gravitation
Bianchi type-VI0 space time with strange quark matter attached to string cloud in Nordtvedt [1] general scalar tensor theory of gravitation with the help of a special case proposed by Schwinger [2] is obtained. The field equations have been solved by using the anisotropy feature of the universe in the Bianchi type-VI0 space time. Some important features of the model, thus obtained, have been di...
متن کاملThe Social Disclosure Impact on Corporate Financial Performance: Case of Big French Companies
The purpose of this paper is to investigate the impact of voluntary disclosure about corporate social responsibility (CSR) on firm’s financial performance. First, a state of the art about corporate social responsibility and social reporting is presented. After that, the problems of measurement of CSR are indicated and the hypotheses are proposed. In the empirical analysis, regression models are...
متن کاملImpact of Vulnerability Disclosure and Patch Availability - An Empirical Analysis
Vulnerability disclosure is an area of public policy that has been subject to considerable debate, particularly between proponents of full and instant disclosure, and those of limited or no disclosure. This paper is an attempt to empirically test the impact of vulnerability information disclosure and availability of patches on attackers’ tendency to exploit vulnerabilities on one hand and on th...
متن کاملInternational Vulnerability Database Alliance as an Effective Vulnerability Disclosure Technique
Vulnerability is one of the key factors that cause security incidents and has become a major international threat to network security. Vulnerability is a weakness which allows an attacker to reduce a system's information assurance. Vulnerability disclosure or the disclosure of a vulnerability is the revelation of a vulnerability to the public at large. Previous work like Common Vulnerabilities ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Information Systems Security
دوره 16 شماره
صفحات -
تاریخ انتشار 2007