All the latest UK technology news, reviews and analysis

TippingPoint sets six-month deadline for flaw fixes

by Iain Thomson

More from this author

04 Aug 2010

Comment: 1

  • Tweet this
Bug code
TippingPoint has taken a stand in the vulnerability disclosure debate

HP's TippingPoint subsidiary has announced a new initiative under which it will release data on software flaws six months after notifying the vendor.

The vulnerability research organisation said that if it has not heard back from a manufacturer about a reported flaw within six months, it will release data on the problem to its customers along with a workaround.

Full disclosure under the Zero Day Initiative will follow, unless an extension to the deadline is worked out in advance.

"Comprehensive protection of critical data assets requires organisations to keep their defences up to date as malicious activity reaches new levels and applications become more complex," said Aaron Portnoy, manager of security research at TippingPoint.

"This policy change is critical for staying ahead of threats so that users can reduce data, financial and productivity loss."

The move will add to the debate over flaw disclosure. Some researchers favour full disclosure to maximise work on the problem, while commercial operators favour a more balanced approach.

"Microsoft advocates co-ordinated vulnerability disclosure, where vendors and finders work together closely towards a resolution," said Dave Forstrom, director of Microsoft's Trustworthy Computing Group.

"Extensive efforts should be made to make a timely response, and only in the event of active attacks is public disclosure, focused on mitigations and workarounds, likely to be the best course of action. Even then it should be co-ordinated as closely as possible."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Software Project Manager, Bristol, up to £35k

Software Project Manager, Bristol, up to £35k Want...

Front End Developer / Web Developer - Tech Start Up - London - Perm

Front-end Developer / Web Developer - Tech Start...

Senior Ruby on Rails Developer - Leading Financial Technology Company

Senior Ruby on Rails Developer - Leading Financial Technology...

Dynamics CRM Technical Consultant £83K + *Incredible Perks*

MS CRM / Dynamics CRM Lead Technical Consultant, £58...

To send to more than one email address, simply separate each address with a comma.