Thursday, October 2, 2008

I Know Something You Don't Know

Responsible disclosure has produced an unwanted side effect. It's the 'I know something that you don't know' disclosure process. There seems to be an increasing trend in the security community to seek the attention provided by full disclosure but retain the praise given to those who stick to 'responsible disclosure'. I was reading an article today which discusses a purported universal TCP DoS attack discovered by Robert E. Lee and Jack Louis who are researchers with the Swedish security firm Outpost24. While they have disclosed the existence of the vulnerability, due to the widespread reach and implications of the issue, they've chosen to withhold details of the attack pending coordination with affected vendors. Based on what little I know of the attack and further insight provided by Robert Hansen, I have no doubt that I'll be thoroughly impressed once details of the attack are finally released. It does however make me uncomfortable to know that the clock is ticking and we can only sit on the sidelines to wait and see if motivated attackers are able to beat vendors to the punch and exploit this vulnerability before it can be patched.

Dan Kaminsky's DNS vulnerability taught us all a lesson that we should have already known - valuable information cannot be contained when others have the motivation and talent to obtain it. Any vulnerability that can be discovered by one researcher can be discovered by another. Stating that a vulnerability exists, simply increases the value of the information - everyone wants it and the race is on. Some will strive to be first, to use the information for personal gain, while others will join the race simply for the challenge. Regardless, once you pull the cork, you can't put the genie back in the bottle.

There are times, when we get stuck between a rock and a hard place. Take for example the situation that unfolded at the OWASP USA 2008 conference last week. Jeremiah Grossman and Robert 'RSnake' Hansen had planned to discuss a new browser attack known as clickjacking. However, at the request of Adobe, they agreed to alter the talk and not proceed with details, to allow Adobe additional time to address the vulnerability. Did they do the right thing? Only time will tell, but under the same conditions, I would have done the same thing. That said, should evidence of widespread clickjacking exploitation emerge, I would hope that Jeremiah and Robert will proceed with disclosing further details, despite the short term potential to exacerbate the problem. While I'm fine with gun control overall, once the war breaks out, I'd appreciate a weapon to defend my family.

The 'responsible disclosure' debate will go on forever and we'll never agree because we all have different motivations. I can buy into situations where full and open disclosure is the lesser of two evils and I can even accept that there are times when remaining silent is necessary. However, in my opinion, yelling 'fire' without saying where just increases the risk that we'll all get trampled.

I'm not naive, I too work for a startup and recognize that the marketing value of such a report is golden. It's far more valuable than any targeted lead-gen that you could ever afford. However, the press isn't going anywhere. They'll still be waiting, just as hungry as ever when coordinated disclosure does finally occur. There is an argument that early publicity will help bring additional vendors to the table to participate in the coordinated disclosure process. While that may be true, groups like CERT or MITRE are well positioned to assist with coordination and can do a great job without the additional hassles of public involvement.

We want to have our cake and eat it too. There's one problem with that - once you take out the cake, the greedy kids want a piece too - and they aren't going to be polite and wait for it to be handed out.

- michael

No comments: