Slashdot Mirror


Sendmail Bug Tests US Dept Homeland Security

yanestra writes "CNET reports that the reported Sendmail bug has been a test for the US Department of Homeland Security which seems to have managed information flow in this case."

15 of 293 comments (clear)

  1. bleh by Joe+the+Lesser · · Score: 5, Insightful

    While keeping news of the issue from leaking to those who might exploit the vulnerability.

    Free flow of information > Security

    --
    "I only speak the truth"
    Karma: null(Mostly affected by an unassigned variable)
    1. Re:bleh by Xzzy · · Score: 4, Insightful

      hardly.

      If the parties involved are actively seeking to fix the problem, in a timely manner, I see no harm in not shouting from the mountain top what the problem is.

      Full disclosure after a patch is done, yes. But doing it before serves no purpose but to conform to some wishy washy idealism and potentially amplifies the damage an exploit could cause.

      And I'm talking in terms of a couple days. If the affected parties hit the snooze button and two weeks roll by, then yes, release the info and make fun of them for the havoc it causes. ;)

    2. Re:bleh by blirp · · Score: 4, Insightful
      I think a timeframe needs to be established. Those who find exploits in programs have a moral obligation to let the maintainers of the program know first and give them a reasonable amount of time to fix the problem.

      But, by definition, if any of the "good guys" have found the problem, it's equally likely that any number of "bad guys" also have found the problem. With exploits in the wild. So telling everybody to be on the look-out, or even close down some services, could easily be the "Rigth Thing(tm)" to do.
      Look, for instance, on all the bad press Symantec drew for keeping info on Slammer to their own customers instead of alerting everybody.

      Actually, this can be argued for ever. And what's rigth in one instance might be wrong in a different... so...

      M.

  2. So what? by da3dAlus · · Score: 5, Insightful

    Are they saying that this worked perfectly? If so, what about the next exploit? What if Joe Nobody finds a hole, and makes it public before the DHS gets with the makers of the software? What about the businesses in the private sector that fail to patch their systems? Wasn't the fix for SQL Slammer out for months? I'm sure this is a step in the right direction, but really, what happens next time?

    --

    Sometimes I doubt your commitment to Sparkle Motion.
  3. Sendmail - too flexible for most by linuxkrn · · Score: 5, Insightful

    Sendmail is a very flexible mail package...too flexible for most people.

    It's power and configuration settings make it a good choice for admins who have taken the time to read on it. However, more often then not we find that there are a lot of lazy admins out there who just get it "up and running" and don't care to understand the security issues with the server. While I've used sendmail for years in the past, but now use postfix. There are a slew of other mail programs out there that can be configured without having to use m4 rules, understand sendmail's rewrite metods etc. I would suggest that if you must have a mail server up, but don't want to take the time to learn sendmail, PLEASE, use something else. I realize this is a little off-topic but it's not too much. It all boils down to securing the net. That takes more then a few bug fixes (and YES you must apply all of them) and a good admin to configure the server/services.

  4. Improved policy? by Jeppe+Salvesen · · Score: 5, Insightful

    Wouldn't it be best to issue a statement like "sendmail has an exploitable vulnerability, we recommend that you switch to your standby alternate mail system until we release a fix"? There is no way that blackhats would figure out where to look from a statement like that, and those of us with really good security could switch to our exim-based solution if we really feared to be hacked. Basically, do we trust the homeland security dept to determine our security policy?

    That being said, good to see a well coordinated patch release. I just wish the paranoids would get advance warning.

    --

    Stop the brainwash

  5. Re:Encouraging by ecalkin · · Score: 5, Insightful

    sadly, i don't see the 'force people to fix security holes' where we need it.

    we have (mostly) good timing getting patches out (even ms gets patches out), but getting end users to *apply* the patches has been a problem. lack of knowledge, time, technical skills, etc.

    at this point, this does seem to be addressed.

    how do we (ahum) fix the end user? my belief is that it should be required that end users have staff/contractors that are certified on their stuff *and* that hey maintain a maintenance log that documents actions or lack of them. if you look at radio stations and the requirements they include licensed radio engineers and logs and other must-dos and must-haves.

    it's time people understood that being connected to everyone else requires a little bit more work.

    eric

  6. DHS versus Early Disclosure by mcgroarty · · Score: 5, Insightful
    If I've got a vulnerable service running on on of my systems, I'd rather know about it right away so I can make the decision as to whether I want to keep it running or temporarily deploy an alternate service.

    I liked the handling of ssh's problems last year much better. "Heads up, there's a problem in these versions. We'll let you know exactly what after we get the patch out." It's not enough to give a hacker a reasonable foot up, but it gets the service off the network should anyone already be quietly taking advantage of the weakness.

  7. Sounds nice but... by captaineo · · Score: 4, Insightful

    It sounds cool to have the US govt leaning on vendors to write patches, but I have a feeling that if this becomes the norm, vendors will just push DHS for longer and longer lead times. The article indicates this particular bug was known since January. Two months is a pretty long time to wait for patches!

    And this is just DHS's "first test" - I imagine after they build up a cozy relationship with the major security-problem vendors (i.e. Microsoft), they might not even disclose any known flaws until patches come out (i.e. months to "never").

    Remember that government officials will probably listen a lot more attentively to "captains of industry" (i.e. MS) than "those unwashed hippy hackers" (i.e. the open-source community).

  8. Re: Dept. of Homeland Security by Black+Parrot · · Score: 5, Insightful


    > Speaking of the Dept. of Homeland Security, here's an link [democratic...ground.org] to an article with some suggestions to Tom Ridge on how to improve his department, so that it actually keeps the citizenry well-informed and aware of possible terrorist threats and how to handle them (as opposed to keeping them scared and in an information blackout).

    You're making a mighty big assumption about what the DoHS was created for.

    --
    Sheesh, evil *and* a jerk. -- Jade
  9. Publicity keeps vendors honest by Anonymous Coward · · Score: 5, Insightful

    Does anybody else find it disturbing that "good security" is being equated with "keeping exploits quiet"?

    It's precisely the threat of publicity that pressures vendors into patching their compromised software quickly. If that threat is relieved, by Official KeepYerDamnMouthShut Orders from a government body, those same vendors may start to think "Phew, now we can wait for the next upgrade".

    This is Not a Good Thing.

  10. hmph... Homeland Security by netwiz · · Score: 4, Insightful

    How exactly is this helping? Control the information flow? How is it then, that links to, and a discussion of, the flaw and possible exploits were publicly available six hours ago on this very website? I wouldn't exactly call a discussion thread on one of the world's largest weblogs "controlling the flow of information."

    This is about the level of competency I've come to expect from Large Government Entities.

  11. Not that bad by siskbc · · Score: 4, Insightful
    FYI, this flaw was actually found in December [msnbc.com] and just reported yesterday, roughly two months later.

    Thanks for the link. You know, I don't think 2 months is exorbitant in this case. As your article states below,

    "Because there are so many different flavors of Sendmail, twenty software vendors had to develop a variety of patches for the flaw..."

    So, they had to patch a ton of different versions, and you don't necessarily want them issuing a shitty patch. So if you blame anyone, blame those sendmail monkeys for the delay. ;) Given the nature of the coordination effort, I think they did quite well.

    --

    -Looking for a job as a materials chemist or multivariat

  12. Full disclosure protects users, even with no patch by ChaosDiscord · · Score: 4, Insightful
    If the parties involved are actively seeking to fix the problem, in a timely manner, I see no harm in not shouting from the mountain top what the problem is.

    The problem is that just because I (an innocent user of the product) don't know about the vulnerability doesn't mean that the evil crackers don't know about it. Sure, a public announcement increases the number of crackers who know about it, but also gives me enough information to react. There is a security hole in sendmail, but no patch yet? Well, without real information, I can't confirm if my particular installation is at risk. Once I know about it, I can take reactive steps. With enough information I could try to patch the vulnerability myself. With enough information I could try to limit my risk (say, changing my sendmail configuration to limit what an attacker can get, or adding a wrapper to detect the attack and terminate the connection). With enough information I reasonably weigh the options of disabling sendmail for security reasons versus keeping it up for my users.

    With no information, I'll just keep ignorantly running the vulnerable version, possibly getting attacked by crackers who already knew about it. With a little information, I don't have enough information to decide if I'm really at risk and to weigh my possible solutions.

  13. Re:Homeland Security by mark_lybarger · · Score: 4, Insightful

    the homeland security is responsible for making us americans feel all warm and fuzzy inside that our government is doing something to protect its citizens on its soil.

    they're responsible for releasing alert warnings every so often. placing the country on a level 3 or orange alert whatever that means, but it sure spikes the sales of bottled water, canned foods, batteries and duct tape for when the big bombs and chemical warfare comes our way.

    to be honest this entire administration has been doing a complete knee-jerk reaction to the WTC and Pentagon events from 2001. they're molding those knee-jerk reactions into something they can use to bomb Iraq and overthrow Suddam because quite frankly there's some big roots in the big state of Texas where "all Your Oil are belong to us"

    here's my favorite quote from the folowwing article:
    http://www.msnbc.com/news/872585.asp?0cl =c1

    That warning regarding tape and three days of water is profoundly helpful to people who are choosing to go to war with Iraq and need to cause an environment of fear in order that the public will do anything to break the fear fever. It serves the administration for the public to be so afraid. When you are afraid enough, you'll get on any train that's leaving the station, even if it is not going where you want to go. That sentence says it all.