Re: Getting Vendors To Fix Bugs


William Westfield (BILLW@MATHOM.CISCO.COM)
Mon 7 Nov 88 11:26:54-PST


Interesting that you should mention X.25 certification as an example.
It is true that the market requires X.25 certification, but the procedures
and tests them selves are pretty much a joke.

The other problem is that I doubt whether you can get "a crack team of
crackers" to spend weeks or months pouring over the source code of some
random operating system looking for security flaws, and still get vendors
to pay only "a reasonable amount". I don't see how this could cost any
less than $100K/release.

There is always the current practice of "beta test at a university", or
"put it on the internet", which is a pretty reasonable test. The weakest
point is still the users..

The sad part about this particular incident is that the sendmail hole
has apparently been known to quite a large number of people for a long
time. (After all, sendmail is not proprietary to any vendor, and
source are widely available.) No one did anything about it. It is
approximately true that the Internet is NOT overly concerned with
security. The current incident has pointed out that perhaps we should
be somewhat more concerned.

Bill Westfield
cisco Systems.
-------



This archive was generated by hypermail 2.0b3 on Thu Mar 09 2000 - 14:44:29 GMT