Comments on: For F-Secure, it's all about the safety net
Kimmo Alkio takes stock of the current state of hackers, attackers, dot-bank domains and mobile phone viruses.
Kimmo Alkio takes stock of the current state of hackers, attackers, dot-bank domains and mobile phone viruses.
December 2, 2009 5:21 PM PST
December 2, 2009 4:37 PM PST
December 2, 2009 4:14 PM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
- security researchers should be held more accountable for security incidents
- by n3td3v June 4, 2007 3:30 PM PDT
- the government need to stop information and tools reaching the cyber terrorists in the first place by making security researchers more accountable for critical disclosures to the public.
- Like this Reply to this comment
-
-
- Accountability begins at home
- by Schratboy June 4, 2007 9:26 PM PDT
- Dude, the technology vendors are digging into exploits just so they can bleat the findings and positions themselves better in the marketplace. Notwithstanding the publicity seekers, every organization should focus on their own knitting: defining what's allowable business processes and zeroing out everything else. However, with sloppy policies and non-existent enforcement, seemingly innocuous employee entertainment opens the door to exploits and data leaks...and everybody is blaming the vendors?!
- Like this View all 2 replies
Processing -
- why can't the government stop hurricans?
- by ColdMast June 5, 2007 7:34 AM PDT
- If flaws were never pointed out patches would never exist. Cyber-Terrorist would only be able to repeat the same attacks over and over again.
- Like this
-
- It's called "Personal Responsibility"
- by RacerX7 June 5, 2007 8:48 AM PDT
- The government is NOT my parent or babysitter.
- Like this
-
(9 Comments)for every security incident that occurs because of a security researcher disclosing information to the public domain, that security researcher should be held accountable.
supplying the bad guys with the tools to carry out the cyber attack should have the same weight as carrying out the cyber attack its self.
we're not saying full disclosure is banned, but what the government should be saying is, if your vulnerability/exploit code/information/tool is used in a cyber attack by someone, then that someone should be jailed or heavily fined as well as the security researcher who originally made it possible for that someone to carry out the cyber attack/security incident in the first place.
it should be the security researcher who decides how critical his disclosure will be and how many security incidents that dislcosure may result in, and its that security researcher who should decide after that if his potential legal position will lead to him being heavily fined or end up in jail or if he decides his disclosure isn't critical then feel happy about making a full disclosure to the public-at-large.
The massive over-spending on IT security is pseudo-comfort for the IT manager (look at how much money I've spent) and for the practitioners of fear, uncertainty and doubt. You're better of buying more than you need because you'll never know when you can be hit. Indeed! The narrow-mindedness of today's end-to-end technology vendors is stupefying and brazen. No technology can assure 100% security. Rule-based technology can't tell you what it missed. Only by examining what happening can you reasonable assess if incidents are held in check or if the wheels are slowly falling off the wagon.
Stop shooting the messengers (technology vendors) and start doing the job you're paid to do...and do it without exceeding your budget year after year.
You act as the digital "enemy" doesn't research their own for exploits.
quote: GOVERNMENT -- should stop information
don't they already
Nor are software vendors.
The security researchers just make vunerabilities public. It doesn't mean they are the first to know about it. By making the public aware of a PRE-EXISTING flaw allows people to take precautions to defend themselves. If a person chooses not to take adequate precautions, that is their problem. Not the government's. Not the researcher's.
You want a 100% safe guarantee? Then unplug your computer and walk away.
Time to stop playing "victim" and take personal responsibility.