Adobe joins Microsoft's patch-reporting program
IDG News Service - Adobe and Microsoft are now working together to give security companies a direct line into their bug-fixing efforts.
By year's end, Adobe will start using the Microsoft Active Protections Program (MAPP) to share details on its latest patches, according to Brad Arkin, Adobe's director of product security and privacy. "The MAPP program is the gold standard for how the software vendors should be sharing information about product vulnerabilities prior to shipping security updates," he said.
Adobe initially wanted to reproduce MAPP, but soon realized that it would take a lot of work to build a program similar to Microsoft's, which was piloted two years ago. Arkin's team began discussions with Microsoft, at first in hopes of picking up some tips. "Eventually, together, we came to the conclusion that it would be a lot more fun to work together on this rather than Microsoft helping us to reinvent the wheel," he said.
Typically, whenever a major patch is released, hackers quickly begin to analyze the patch to see what flaws were fixed. They then rush to work out attacks that would exploit the vulnerability on unpatched products.
Adobe has been hit hard in the past two years by hackers who have found bug after bug in the company's products. This often means hard work for security companies, who must scramble to add detection for these attacks.
It's become so bad that one security company, SourceFire, is holding an exclusive Adobe Hater's Ball on Wednesday here at the Black Hat security conference in Las Vegas.
The Ball is really a tongue-in-cheek joke, modelled on comedian Dave Chappelle's Playa Hater's Ball.
"My guys have a love-hate relationship with the guys over at Adobe," said SourceFire Director Matt Watchinski. "Every time a vulnerability comes out of their stuff, we have to jump."
Arkin said he and other Adobe researchers will be at the event.
With Adobe jointing the MAPP program, however, security companies like SourceFire should do less scrambling.
MAPP gives them early notice on upcoming patches -- typically about 48 hours -- so they have more time to build attack detection into their security systems. About 65 security companies participate in MAPP. All of them will soon start getting the Adobe data.
This is the first time that Microsoft has extended the MAPP program to cover another company's products, said Dave Forstrom, a director with Microsoft's Trustworthy Computing group.
However, it may not be the last. Forstrom didn't rule out the possibility that other software vendors could also jump on board.
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com
- Secretive group seeks recruits at Defcon, finds skepticism
- Hacker snoops on GSM cell phones in demo
- Free Android apps scrape personal data, send it to China
- U.S. should seek world cooperation on cyber conflict, says ex-CIA director
- 'Unhackable' Android can be hacked, Black Hat researchers say
- Update: ATM hack gives cash on demand
- BitBlaze tool boosts bug-hunting productivity 10-fold
- Apple patches Safari ahead of Black Hat talk, launches add-on gallery
- Black Hat: Most browsers can be made to give up personal data
- AT&T: We don't intend to stop Black Hat demo
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- File Archiving - The Next Big Thing or Just Big This white paper from Osterman Research discusses best practices for archiving file-based content and offers some recommendations about how organizations should manage the...
- 3 Steps to Unlock Savings from Legacy Applications Explore a three step process to free your business from unnecessary costs and to protect your business from unnecessary risks.
- Red Hat JBoss Fuse Compared with Oracle Service Bus Competitive Brief Read this paper to learn how to start more projects, deploy technology more pervasively within the enterprise, and apply more of your budget...
- Red Hat JBoss BRMS Best Practices Guide Learn the technical best practices for development with Red Hat JBoss Enterprise BRMS. Following the best practices outlined in these guides will result...
- Boost Performance & Profitability with Better Planning & Mobile Reporting This session will discuss how Ashurst, a top-tier legal service provider for private and public sector clients worldwide, was able to effectively manage...
- Apps and BlackBerry 10 - Tips for IT Learn how to easily create, deploy and manage both off-the-shelf and custom apps, improving productivity and efficiency for employees by mobilizing apps, processes... All Applications White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!
