(Mis)Uses of Technology

(Mis)Uses of Technology

by Mike Masnick




Security By Obscurity Doesn't Stop The Negative Day Exploits

from the just-saying... dept

This would be the latest in our ongoing series of stories about how the standard way of dealing with security problems doesn't really work any more. It relies on a system of discovering the vulnerability, figuring out how to stop it, and then distributing a patch widely. That works for incredibly slow moving malware -- but, if you hadn't noticed, malware is learning how to spread ever faster. For years people have warned that this was going to lead to "zero-day attacks" where exploits are propagating before anyone has the chance to patch. That's already started happening in many cases, and it demonstrates, again, why the "security by obscurity" argument some companies make, saying that everyone needs to stay quiet until they've patched their systems, is bogus. For example, the WMF exploit that got so much attention last month apparently was available on the black market for nearly a month before security firms started discussing it. In other words, any company that thinks keeping a security exploit quiet to prevent those with malicious intent from figuring it out are probably fooling themselves. Those with malicious intent already probably have it figured out.

1 Comments | Leave a Comment..

 
 

Reader Comments (rss)

(Flattened / Threaded)

  1. Feb 3rd, 2006 @ 1:18am

    Did you miss the Elves in huge costumes broken int


    You are a dark elf. You do love, but if anyone
    found out, they'd be toast. You are not evil,
    but you like people to think you are!
    What elf are you? *sweet anime pic*
    brought to you by Quizilla

    (reply to this comment) (link to this comment)

Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie
  • Plain Text: A CRLF will be replaced by break <br> tag, all other allowable HTML is intact
  • HTML: No formatting of any kind is done without explicitly being written in
  • Allowed HTML Tags: <b> <i> <p> <a> <em> <br> <strong> <blockquote> <hr> <tt>
Close
Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie

Search Techdirt
And now, a word from our Sponsors..



Subscribe to Techdirt's Daily Email Newsletter

Techdirt's Daily Email Newsletter

Related Stories
Close
E-mail It