All the latest UK technology news, reviews and analysis

Microsoft worms its way off bug list

by Linda Leung in Silicon Valley

09 Dec 2000

Be the first to comment

  • Tweet this

Microsoft has told Security Focus, the US security company that manages the Bugtraq moderated security email list, that it can no longer publish the software giant's security alerts.

The issue centres around Microsoft's recently redesigned security email alerts, which it distributes to registered subscribers and third-party security mailing lists.

The redesigned bulletins give only the barest details about new vulnerabilities and instead direct users to a page on Microsoft's website for the full text.

Under the original email format, which included full text, Bugtraq was able to redistribute the alerts because Microsoft had sent them to Bugtraq. But in response to a Microsoft vulnerability email alert issued in the new format earlier this week, Bugtraq moderator Elias Levy republished the full text, which he downloaded from Microsoft's website.

This solicited an angry response from Microsoft, which told Levy that he did not have permission to redistribute the text, and that doing so would be considered an act of copyright violation.

Ryan Russell, management information systems manager at Security Focus, said Levy decided not to approve alerts that do not provide full text, and downloaded the information from Microsoft's website so that Bugtraq readers would get additional details.

"Microsoft's new format is not as useful as the old format. You've got to launch a new browser to see the full text and it seems to work better when viewed on Internet Explorer than Netscape," said Russell.

Other Bugtraq recipients have complained that the new format points users to one point of failure, and warned that emails addresses can be spoofed with links provided to a malicious site.

Russell said Bugtraq would return to redistributing Microsoft alerts if the software giant goes back to the old format.

Microsoft failed to comment.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

2%

15%

52%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Technical Consultant, Back Office (IMMEDIATE STARTERS)

THIS ROLE IS LOOKING AT IMMEDIATE STARTERS AND WITH MULTI...

Sales Consultant - Datacentre

Sales Consultant - Data Centre, Colocation, Hosting...

Senior Interaction Designer (User Experience, UCD, Prototypes)

Senior Interaction Designer (User Experience, UCD, Interactive...

Head of Information Architecture / UX - London - £370p/d

Information Architecture / IA / User Experience / UX...

To send to more than one email address, simply separate each address with a comma.