main
Report a problem

Microsoft to hackers: Don't publish code

Steven Parker   on 17 October 2001 - 23:56 · no comments & 135 views

Advertisement (Why?)
Thanks Bain for this, Microsoft, whose software has been at the center of several recent high-profile security incidents, has decided to turn up the heat on those the company considers at least partially responsible: security firms and hackers who release sample programs to exploit software flaws.

This week, Scott Culp, manager for Microsoft's security response center, published an essay on the company's site decrying the information and example code released by some companies and independent security consultants as "information anarchy."

Such information led directly to many of this year's most vicious worm attacks, he said.

"It's high time the security community stopped providing the blueprints for building these weapons," Culp wrote in the essay. "And it's high time that computer users insisted that the security community live up to its obligation to protect them."
The essay reopens the debate among security professionals over whether information on software flaws should be kept confidential or freely publicized.

News source: CNet

Post a comment · Send to friend Comments · There are no additional comments

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)