Microsoft charts security vuln MAPP
Exploitability index labels #
Posted Tuesday 5th August 2008 19:25 GMT
"The exploitability index will contain labels assigned to each vulnerability, including "consistent exploit code likely," "inconsistent exploit code likely" and "functioning exploit code unlikely," which would translate into higher, medium and lower priority."
MS is making a good step forward (hopefully and potentially) in helping the security community, BUT will Average Joe User understand correctly those index labels? Because, the way that article read, those labels are being directed at the average home user to judge their computer's current security/vulnerability. Don't throw technical jargon at the average user, it tends to only confuse and further aggravate.
Erm, Am I missing something here? #
Posted Wednesday 6th August 2008 00:02 GMT
"Redmond will provide security providers with detailed information about upcoming updates. The disclosures will include instructions on how to reproduce and exploit the vulnerabilities"
Don't they do that (reverse patches) already?, or does this mean that these people will be handpicked to get the stuff way before your average joe hacker?.
Oh wait, now I get it... The smart ones already know how to do this, only the "less smart" ones that need the instructions so they get it before hand
Right!
I stand to be corrected!
This is a bunch of marketing crap #
Posted Wednesday 6th August 2008 08:56 GMT
Information about the upcoming vulnerability patches, eh? Well, let me tell you about it.
Microsoft *already* provides to the AV people (after they have signed an NDA, of course) "information" about the vulnerabilities patched by the current patches - including information how to reproduce the problem and how to detect it. Sounds great, right?
Yeah, but.
Often this information is incomplete and totally useless. When we complain, they tell us that "only this is available at this time". Of course, nothing additional is ever available at a later time. Worse, Microsoft's algorithms for detecting these vulnerabilities are often discovered to be incomplete or (even more often) to cause false positives. When we complain, we get the standard answer that "Microsoft does not have the resources to investigate old and already patched vulnerabilities", which is just a polite way of saying "screw you".
What a bunch of moronic idiots. :-(
Maybe ... #
Posted Wednesday 6th August 2008 08:56 GMT
Maybe this is at least partly a response to the great ZoneAlarm / Windows Update cock-up of a few weeks ago, where a security update knocked loads of ZA users off the Internet.
If the other vendors (ZA in that particular case) can get more and better information from Microsoft about both the vulnerability and about the upcoming patches designed to fix said vulnerability, surely that reduces the chance of a similar scenario in the future.
MAPP looks like a good move to me.
Disclosure is good #
Posted Wednesday 6th August 2008 09:03 GMT
This is a step into the right direction. I hope they are not creating a problem for themselves by this limited disclosure approach - there will always be leaks to black-hats. What happens if it turns out that a black-hat used this information for attacks?
Anyway, I take IDS signature writers and others will welcome this information.
@This is a bunch of marketing crap #
Posted Wednesday 6th August 2008 16:13 GMT
It's still far better than the Apple wall of silence
Popular Whitepapers
- Comparison Guide: IP Phones
Exact details on specific IP Phone features such as function buttons, display resolution, weight and price - Market Primer: ERP Systems
Still stuck in the clouds when in comes to ERP? - The top 5 server monitoring battles
And how you can win them - Breakthrough advantage with the IBM System Blue Gene/P solution for exploration and production
A tectonic shift in upstream petroleum - Straight Talk with Dell: Sending out an SaaS
On Demand Webcast - Analyst Keynote: The Register Agile Data Center Summit
On-Demand: Audio with slides