If a vendor finds a vulnerability in a competitors code are they obligated to tell them? What exactly is ethical and or responsible disclosure when it comes to competing vendors? Among security researchers the general consensus these days is to notify the vendor and then wait a reasonable amount time for a patch to be developed before going public. While this scenario is for the most part agreed upon and followed it is by no means a perfect solution. Now through in competing vendors and it gets even stickier.
Recently the Mozilla group was notified of an exploit in their code which they dutifully fixed. In the process they evidently realized that the same hole effected the Opera browser. Like good net citizens they notified Opera of the hole but did not wait around for Opera to fix it.
So is Opera justified in being a little miffed at Mozilla for not waiting for a fix or should they be happy that they got notified at all? Should vendors be held to the same ethical standards as researchers when it comes to vulnerability disclosure even if it is with a competitors product? Why have we had this same problem for decades without some sort of solution?
About Space Rogue
With over two decades of experience, Space Rogue (Cris Thomas) has testified before the U.S. Senate Committee on Homeland Security and Governmental Affairs, and has been interviewed by Wired, CNBC and even MTV. He created the wildly popular websites the Whacked Mac Archives and Cyber Squirrel 1. He produced the weekly podcast SpiderLabs Radio, and the critically acclaimed weekly news video program the Hacker News Network. His writing has appeared in Network Computing, New Statesman, The Hill, and the Christian Science Monitor. He has spoken at security conferences such as Def Con, Blackhat, and Shmoocon. Space Rogue currently works as the Global Lead of Policy and Special Initiatives for the legendary IBM X-Force.
Responsible disclosure for vendors?
If a vendor finds a vulnerability in a competitors code are they obligated to tell them? What exactly is ethical and or responsible disclosure when it comes to competing vendors? Among security researchers the general consensus these days is to notify the vendor and then wait a reasonable amount time for a patch to be developed before going public. While this scenario is for the most part agreed upon and followed it is by no means a perfect solution. Now through in competing vendors and it gets even stickier.
Recently the Mozilla group was notified of an exploit in their code which they dutifully fixed. In the process they evidently realized that the same hole effected the Opera browser. Like good net citizens they notified Opera of the hole but did not wait around for Opera to fix it.
So is Opera justified in being a little miffed at Mozilla for not waiting for a fix or should they be happy that they got notified at all? Should vendors be held to the same ethical standards as researchers when it comes to vulnerability disclosure even if it is with a competitors product? Why have we had this same problem for decades without some sort of solution?
About Space Rogue
With over two decades of experience, Space Rogue (Cris Thomas) has testified before the U.S. Senate Committee on Homeland Security and Governmental Affairs, and has been interviewed by Wired, CNBC and even MTV. He created the wildly popular websites the Whacked Mac Archives and Cyber Squirrel 1. He produced the weekly podcast SpiderLabs Radio, and the critically acclaimed weekly news video program the Hacker News Network. His writing has appeared in Network Computing, New Statesman, The Hill, and the Christian Science Monitor. He has spoken at security conferences such as Def Con, Blackhat, and Shmoocon. Space Rogue currently works as the Global Lead of Policy and Special Initiatives for the legendary IBM X-Force.