Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Bag the Gag Rule

November 26, 2001 12:00 PM ET

Computerworld - This Wednesday marks Day 30 since the Nimda.e worm showed up on the Internet. Microsoft and a few of its security cronies would have us believe that 30 days is about the right amount of time for everyone to shut up about any particular security vulnerability. The idea, floated by the group after Microsoft's Trusted Computing Forum this month, is that the IT industry should agree on a "grace period," during which the affected software vendor can fix the problem and issue patches without worrying about information on the vulnerability leaking out. After all, what could happen in 30 days?
Well, at the U.S. District Court for the Southern District of Florida, 30 days is long enough to turn the clock back 30 years.
Two days after it was discovered in the wild, Nimda.E hit the court's offices in Miami. By the following Monday - Day 8 - PCs were crashing left and right.
On Day 10, the court reverted to doing everything the old-fashioned, noncomputerized way. It might have been 1971 instead of 2001. Forms were filled out by hand, and clerks used phones instead of networks to get information on defendants and cases in other cities.
By Day 15 - halfway through the 30-day "grace period" - the court's Web site still was not back up, and IT staffers were still cleaning Nimda.E off PCs one at a time.
Oh yeah, keeping a lid on a security problem for 30 days - that'll sure protect us.
But it's not intended to protect us, is it?
Microsoft has a problem, and nobody in Redmond doubts it. Hardly a week goes by without some Microsoft product - Web browser, Web server, office application, e-mail client, operating system - hitting the news because it has a security vulnerability.
But the 30-day gag rule that Microsoft and its tame security partners are proposing won't reduce the risk for the users of those products. It will just reduce the risk to Microsoft's reputation from the weekly public relations problems.
That 30 days isn't just for coming up with a patch. It's an entire month to spin the bad news.
No wonder Microsoft wants the whole industry to take the 30-day pledge. The company with the security problem gets to tell its version of the story publicly when it issues its patch. Competitors promise to keep their mouths shut for a month after it's discovered.
Meanwhile, nobody is suggesting that crackers will observe any 30-day moratorium after they discover a security hole. Of course



Jump to comments

Security

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

White Papers & Webcasts

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.  

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Why Email Must Operate 24/7 and How to Make This Happen
Learn how to avoid an email outage by implementing a hosted email continuity solution.  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...