On MovieTome: Amazing new STAR TREK pics are online!
BNET Business Network:
BNET
TechRepublic
ZDNet

May 6th, 2008

Do we need another CERT?

Posted by Dana Blankenhorn @ 7:15 am

Categories: General, Infrastructure, Security, Distributions, support, Google

Tags: Vulnerability, CERT, Windows Machine, Dana, Security, Open Source, Dana Blankenhorn

Window of VulnerabilityYes.

Google’s backing of oCERT is a major milestone in the history of open source.

It’s not that I have anything against the Computer Emergency Response TeamCERT at Carnegie-Mellon. They do important work, not only in identifying risks but in educating people on them.

UPDATE: A CERT spokesman notes they’ve licensed the term, dropped the longer form of the name (like IBM did back in the day) and licensed it to oCERT.

What makes oCERT important is here, in the famous 2000 essay by Bruce Schneier on the “window of vulnerability.”

As Schneier noted, vulnerabilities, like fame, have five distinct phases.* A vulnerability is discovered, announced, becomes popular, gets patched, and then the patch is disseminated.

It’s the last bit where the differences lie in open source. Windows machines are patched centrally, and that patch is distributed widely, quickly, sometimes forcefully.

Whether you get your patches directly from Microsoft or from a security vendor, the process is the same.

We have a well-established protocol for distributing fixes, so that curve downward, from distribution of a patch to fixing it, is sharp. It’s like herding cows.

While open source doesn’t suffer as many vulnerabilities, its dispersed nature makes fixing them more like herding cats than cows.

A central system like oCERT is needed so that, as open source gains market share, and malware writers target Linux, we can keep that last curve sharp.

* The five stages of fame. Who’s Dana? Get me Dana! Get me someone like Dana! Get me a young Dana! Who’s Dana? Insert your name for mine.

Dana Blankenhorn has been a business journalist for 30 years, a tech freelancer since 1983. See his full profile and disclosure of his industry affiliations.

Email Dana Blankenhorn

  • Talkback
  • Most Recent of 5 Talkback(s)
First part was a joke.. and linux had it before MS along with lots of other
software.

As far as my linux comment, i dont use red hat, i have messed with it and have seen an update feature.

I run two slackware servers and one AIX server, so yes i know linux and i also know unix, but i dont know every aspect of both, do you?... (Read the rest)
Posted by: Been_Done_Before Posted on: 08/03/08 You are currently: Logged In | Log out
what linux/unix taking a queue from MS Been_Done_Before   | 05/06/08
Huh??? storm14k   | 05/06/08
First part was a joke.. and linux had it before MS along with lots of other Been_Done_Before   | 08/03/08
best practices are still best practices...... shryko   | 05/07/08
THIS IS FUD!!! shryko   | 05/07/08

What do you think?

No Trackbacks Yet

The URI to TrackBack this entry is:
http://blogs.zdnet.com/open-source/wp-trackback.php?p=2392

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

CIO Sessions

advertisement
Click Here