ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Microsoft: No plans to pay for security vulnerabilities

By | July 23, 2010, 8:47am PDT

Summary: A Microsoft security official dismissed any suggestion that the company would start buying rights to security flaws, arguing that its current system of crediting hackers in security bulletins is working very well.

Mozilla and Google may be increasing the bounties to security researchers who find security holes in their software products but don’t expect Microsoft to join the pay-for-flaws party.

According to Threatpost’s Dennis Fisher, a Microsoft security official dismissed any suggestion that the company would start buying rights to security flaws, arguing that its current system of crediting hackers in security bulletins is working very well.

Here’s what Microsoft’s Jerry Bryant told Fisher:follow Ryan Naraine on twitter

“We value the researcher ecosystem, and show that in a variety of ways, but we don’t think paying a per-vuln bounty is the best way. Especially when across the researcher community the motivations aren’t always financial. It is well-known that we acknowledge researcher’s contributions in our bulletins when a researcher has coordinated the release of vulnerability details with the release of a security update.”

“While we do not provide a monetary reward on a per-bug basis, like any other industry, we do recognize and honor talent. We’ve had several influential folks from the researcher community join our security teams as Microsoft employees. We’ve also entered into contracts directly with many vendors and sometimes individual researchers to test our products for vulnerabilities before they’re released. Many of these vendors and individuals first came to our attention based on the high-quality and unique approaches demonstrated by the vulnerabilities they reported to the MSRC.”

GOOGLE’S 60-DAY DEADLINE

Microsoft’s stance comes on the heels of increased discussion around vulnerability disclosure.  For starters, a team of Google researchers is pushing software vendors to ship security patches within 60 days.

Whilst every bug is unique, we would suggest that 60 days is a reasonable upper bound for a genuinely critical issue in widely deployed software. This time scale is only meant to apply to critical issues.

This stance by Google is in effect an endorsement of the move by its own Tavis Ormandy to release details of a Windows zero-day bug after claiming Microsoft declined to commit to fixing the issue in 60 days.  Microsoft denies it failed to commit to a deadline because it was still investigating the issue.

[ Googler releases Windows zero-day exploit, Microsoft unimpressed ]

Following Google’s blog post that outlines its stance on disclosure, Microsoft followed suit and announced a shift in its approach to disclosure.  The company said it will embrace the concept of Coordinated Vulnerability Disclosure (CVD) which, in some cases, will allow the release of information ahead of a patch if attacks are underway.

Microsoft’s Katie Moussouris explains:

Responsible Disclosure should be deprecated in favor of something focused on getting the job done, which is to improve security and to protect users and systems. As such, Microsoft is asking researchers to work with us under Coordinated Vulnerability Disclosure, and added some coordinated public disclosure possibilities before a vendor-supplied patch is available when active attacks are underway. It uses the trigger of attacks in the wild to switch modes, which is an event that is objectively observable by many independent sources.

Make no mistake about it, CVD is basically founded on the initial premise of Responsible Disclosure, but with a coordinated public disclosure strategy if attacks begin in the wild. That said, what’s critical in the reframing is the heightened role coordination and shared responsibility play in the nature and accepted practice of vulnerability disclosure. This is imperative to understand amidst a changing threat landscape, where we all accept that no longer can one individual, company or technology solve the online crime challenge.

Microsoft is expected to discuss this philosophical shift with researchers at this year’s Black Hat security conference.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

34
Comments

Join the conversation!

Just In

Dough mixer
dough rounder 9th Jan
I'm starting a blog soon but have no coding knowledge so I wanted to get advice from someone with experience. Any help would be greatly appreciated!
Hi there! I just wanted to ask if you ever have any trouble with hackers?
know more information please contact me (Michael Ling ) http://www.chinacateringequipment.com

http://www.marklinecatering.com/
0 Votes
+ -
Seeing how Microsoft is doing better than the average
honeymonster Updated - 23rd Jul 2010
and better than almost all 3rd party software both in respect to number of vulnerabilities found (fewer) and patching time, I can understand that position.

MS platforms and software are still subject to be scrutinized, bounty or not. Other vendors may fear what will happen once their platform receives the same level of attention. And to act before the disaster, paying per bug may make sense.

But in MS case they would merely be competing with the black hats, increasing the price "security researchers" can demand on the black/gray market.
@honeymonster Did you realize such professionals could compose custom papers of very high quality. Thus, you had to buy essay to be successful. essay writing help
@jamesaustinwarn then you fall out of favor with them! I simple can't dislike a person, just because someone else does, I just can't. High School Diploma
MS platforms and software are still subject to be scrutinized, buy essay bounty or not. Other vendors may fear what will happen once their platform dissertation writing receives the same level of attention. And to act before the disaster, paying per bug may make sense.
This is such a great thing to know "???While we do not provide a monetary reward on a per-bug basis, like any other industry, we do recognize and honor talent. We???ve had several influential folks from the researcher community join our security teams as Microsoft employees. We???ve also entered into contracts directly with many vendors and sometimes individual researchers to test our products for vulnerabilities before they???re released" thanks a lot for sharing...

Background Check Rental
0 Votes
+ -
Its funny because a few years back Microsoft did the whole bounty thing and was criticized harshley for it. Now Mozilla and Google are doing it and its suddenly cool.
0 Votes
+ -
@Loverock Davidson

please supply references to support this
@erik.soderquist Thanks for sharing. i really appreciate it that you shared with us such a informative post..
Thesis Dissertation Admission Essay
@erik.soderquist I will forward this article to him. Pretty sure he will have a good read. Thanks for sharing!
Essay Assignments
Responsible Disclosure should be deprecated in favor of something focused on getting the job done, which is to improve security and to protect users and systems.
realsoft technologies
I would add something witty like "MicroSoft doesn't pay, its customers do" but I'm not the sort of guy that makes such remarks.
@zdnet@...

No need to add anything more to that ........ Apple rules
0 Votes
+ -
Wait!
statuskwo5 20th Aug 2010
@SoYouSaid Apple pays people to find vulnerabilities in their software?
@zdnet@... I'm the same way, I do my best to remain neutral. It's hard, if you communicate with the person the other person dislikes, then you fall out of favor with them! I simple can't dislike a person, just because someone else does, I just can't.
IAO IAO Accreditation International Accreditation Organization
@zdnet@... The difference between the right word and the almost right nation high school word is really a large matter ??? it's the online education difference between a lightning bug and the lightning.
These are the kind of self serving irresposible stands by industry leaders that force the government to take action when the general public good is affected.
Kinda like waving a red flag in front of a bull while forgetting there is no fence to keep it from you!
DUMB, DUMB, AND DUMBER!
@kd5auq

If by "action" you mean create a dozen new committees that use billions of dollars to determine that we need to do something someday, but never actually do that thing, you'd be absolutely right.

Frankly, the industry's irresponsibility is 1000x more responsible than the government's responsibility.
0 Votes
+ -
The top reasons:
wackoae 23rd Jul 2010
There is a big chance it will go bankrupt by paying a decent bounty (not just pennies as before). With the bounty comes the responsibility to FIX the vulnerabilities ... adding to the cost of the bounty. To minimize payments, MS will be forced to disclose vulnerabilities they knew for years, but didn't fix ... opening the door for possible legal repercussions and the loss of new contracts.
@wackoae : Who's going bankrupt? Microsoft? Get real. Chances of Microsoft going bankrupt is like Steve Jobs admitting there is a real problem with the iPhone 4 antenna issue. Very, very, very unlikely.
0 Votes
+ -
Hahaha!
statuskwo5 20th Aug 2010
@Gis Bun That was funny.
Don't you just love this statement: "a team of Google researchers is pushing software vendors to ship security patches within 60 days". Who made Google god?

There is a difference when you have [let's say the Mac OS X with a ~7% OS share and Windows with a ~85% share. Plenty of people to check/test for Windows issues compared to OS X.
0 Votes
+ -
@Gis Bun

You believe in the Apple seeded notion that OS X has fewer vulnerabilities.

It is not so. The hard (outside the RDF) reality is that OS X has 3 times more vulnerabilities found. Has been like that for ages now.

This has been demonstrated over and over again, independently by IBM X-force labatories, and by Secunia.

You can indeed make the argument that OS X probably has even more undiscovered vulns because presumably fewer people are looking for them.

But your market share argument primarily affects how many people are willing to write exploits against those vulnerabilities.

Windows has 10-20 times the market share of OS X. An OSX exploit has to be 10-20 times (hit and infect 10-20 times more machines) more effective than a Windows exploit in order for attackers to pay attention. Otherwise they will just keep on using their tooling for Windows.

This is about to dry up. Windows Vista and Windows 7 has so many hoops and barriers to climb that infection rate (attacker success rate) is much lower on these machines. This will eventually tip attackers attention towards the mostly unprotected and highly vulnerable OS X. Times up. Security through mac obscurity is ending.
0 Votes
+ -
Shame on MS
rupaa62 27th Jul 2010
My opinion if someone finds a flaw they should taunt MS saying I found a flaw, give them little bit about it but nothing to tell them where it is. This way MS has to look into it. If they want the product to work right and happy customer they should pay these people who are doing the work what MS people should be doing. Would you like happy customers or angry customers and a class action lawsuit for flaws that you know. This should not be for just MS but to all tech companies. Tech comes out so quick becuase each company wants to make a cheap buck off of the public. Its like all products of today they are all cheaply made no loyality to the customers anymore just loyality to the stock holders.
I really liked your article.. You gave such a informative and useful post.. I appreciated your kind way of knowledge... Great stuff here hope more to come.... Essay Writing || Write My Essay || Essay Help || Dissertation Proposal
I think Microsoft management take a write decision to do not purchase software security because it has a lot of professional employees for protect their software. essay writing , buy essay online , essay writers , write my essay
MS platforms and software are still subject to be scrutinized, buy essay bounty or not. Other vendors may fear what will happen once their platform dissertation writing receives the same level of attention. And to act before the disaster, paying per bug may make sense.
MS platforms and software are still subject to be scrutinized, buy essay bounty or not. Other vendors may fear what will happen once their platform receives the same level of attention. And to act before dissertation writing the disaster, paying per bug may make sense.
0 Votes
+ -
ice machine
ice makers 10th Nov
it and also added your RSS feeds, so when I have time I will be back to read much more, Please do keep up the superb job.http://www.cbfi-icemachine.com
0 Votes
+ -
hang tags
ice machine 11th Nov
I've tried it in two different web browsers and both show the same outcome.http://www.bestgarmentaccessories.com/
0 Votes
+ -
dough rounder
dough rounder 8th Dec
Hi there! Quick question that's entirely off topic. Do you know how to make your site mobile friendly? My blog looks weird when browsing from my apple iphone. I'm trying to find a template or plugin that might be able to correct this issue. If you have any recommendations, please share. Thank you!
I???m not that much of a internet reader to be honest but your sites really nice, keep it up! I'll go ahead and bookmark your website to come back later. Many thanks
I really like your blog.. very nice colors & theme. http://www.chinacateringequipment.com
know more information please contact me (Michael
Ling ) dough??mixer??
0 Votes
+ -
Dough mixer
dough rounder 9th Jan
Did you create this website yourself or did you hire someone to do it for you? Plz answer back as I'm looking to design my own blog and would like to find out where u got this from. thanks a lot
Wow! This blog looks exactly like my old one! It's on a completely different topic but it has pretty much the same page layout and design. Superb choice of colors!
Hey just wanted to give you a quick heads up and let you know a few of the images aren't loading correctly. know more information please contact me (Michael Ling ) http://www.chinacateringequipment.com

http://www.marklinecatering.com/
0 Votes
+ -
Dough mixer
dough rounder 9th Jan
Did you create this website yourself or did you hire someone to do it for you? Plz answer back as I'm looking to design my own blog and would like to find out where u got this from. thanks a lot
Wow! This blog looks exactly like my old one! It's on a completely different topic but it has pretty much the same page layout and design. Superb choice of colors!
Hey just wanted to give you a quick heads up and let you know a few of the images aren't loading correctly. know more information please contact me (Michael Ling ) http://www.chinacateringequipment.com

http://www.marklinecatering.com/
0 Votes
+ -
Dough mixer
dough rounder 9th Jan
I'm starting a blog soon but have no coding knowledge so I wanted to get advice from someone with experience. Any help would be greatly appreciated!
Hi there! I just wanted to ask if you ever have any trouble with hackers?
know more information please contact me (Michael Ling ) http://www.chinacateringequipment.com

http://www.marklinecatering.com/

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix