Google Security Pushes for 7-Day Vulnerability Publishing
May 30, 2013 2:29 PM
comment(s) - last by
This could encourage companies to issue security patches more quickly
is backing a new seven-day deadline that would allow researchers to make serious vulnerabilities public a week after notifying a company.
Google security engineers Chris Evans and Drew Hintz said they want critical vulnerabilities under active exploitation to be published seven days after researchers have informed the company about them. They said this will lead to quicker patches and cut the risk of further problems in the future.
“Our standing recommendation is that companies should fix critical vulnerabilities within 60 days — or, if a fix is not possible, they should notify the public about the risk and offer workarounds,” said Evans and Hintz. “We encourage researchers to publish their findings if reported issues will take longer to patch. Based on our experience, however, we believe that more urgent action — within seven days — is appropriate for critical vulnerabilities under active exploitation. The reason for this special designation is that each day an actively exploited vulnerability remains undisclosed to the public and unpatched, more computers will be compromised.”
Right now, companies use either responsible disclosure or full disclosure when dealing with vulnerabilities. Responsible disclosure allows a company as much time as they want to patch an exploit, and the details surrounding the bug aren't revealed to the public until a patch is issued. Full disclosure, on the other hand, means the company and the public are given information about the flaw at the same time.
Three years ago, Google's security team introduced a 60-day notice in order to find a happy medium between the two disclosures. This meant that researchers could publish details about a flaw for the public to see after 60 days whether a patch was issued or not.
But it looks like Google is taking this a giant step further by advocating a new seven-day deadline, where researchers can make details about a flaw public only a week after telling the company about it.
However, Google realizes that seven days is not enough time to patch all vulnerabilities. Even if a company can't address the bug in seven days, the researchers could still publish the details of the software flaw after a week so that the public can protect itself.
Earlier this month, Google security engineer Tavis Ormandy
exposed a Microsoft flaw
on Full Disclosure. The Microsoft vulnerability, which was in the Windows kernel driver "Win32k.sys," was featured in a Full Disclosure mailing list on May 17.
Ormandy also insulted Microsoft on Full Disclosure, saying "As far as I can tell, this code is pre-NT (20+ years) old, so remember to thank the SDL for solving security and reminding us that old code doesn't need to be reviewed ;-)."
Microsoft has been annoyed with Ormandy for publicly discussing vulnerabilities before they could be patched. Microsoft prefers "responsible disclosure," where security experts are asked to report flaws privately to the company.
Google Online Security Blog
This article is over a month old, voting and posting comments is disabled
google advisory notice
5/31/2013 9:46:20 PM
Yep... Look at any blog on Daily Tech and get a nice big red REPORTED ATTACK PAGE! notice, followed by a google advisory as to how offensive this page REALLY IS!
I chose to ignore it...
"We don't know how to make a $500 computer that's not a piece of junk." -- Apple CEO Steve Jobs
Google Engineer Finds Microsoft Security Flaw, Says Company is Hostile About It
May 23, 2013, 10:51 AM
Twitter Senior VP: "Diversity is Important, But We Can’t Lower the Bar"
November 9, 2015, 9:59 AM
CNN Resorts to Internet Censorship to Promote Clinton Over Senator Sanders
October 15, 2015, 2:47 PM
Breaking Bad: How to Crash Google's Chrome Browser With Just 8 Characters
September 23, 2015, 11:08 AM
Quick Note: Amazon UK Offers £10 Back on Any Order £50 or Over
August 3, 2015, 12:05 PM
Editorial: Reddit Allows Itself to be Hijacked as a Hate Platform For Racist Bigots
July 21, 2015, 6:32 PM
Mozilla and Facebook to Adobe: It's Time to Kill Flash
July 20, 2015, 6:30 PM
Most Popular Articles
First Apple Computer Auctions for $815,000
August 27, 2016, 7:51 AM
Drones at the Airport
August 26, 2016, 5:00 AM
5 Easy Ways to Lower Blood Pressure By Monique C. Bethell, Ph.D.
August 25, 2016, 8:00 AM
2 NEW PlayStation 4 Models - Unveiling September 7th
August 23, 2016, 6:23 AM
Say Goodbye to Data Plans - Sprint and T-Mobile offer Unlimited Data
August 22, 2016, 6:12 AM
Latest Blog Posts
First Self-Driving Car debut on the streets of Singapore
Aug 28, 2016, 4:10 PM
Coming Soon - Drones and Airports
Aug 24, 2016, 12:40 PM
SolarCity’s Gigafactory: A Milesone in Emerging Technology by Lily Emamian - 15 August 2016
Aug 15, 2016, 6:30 AM
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
More Blog Posts
Copyright 2016 DailyTech LLC. -
Terms, Conditions & Privacy Information