MS To Share Early Flaw Data With Governments
Trailrunner7 writes "Microsoft today announced plans to share pre-patch details on software vulnerabilities with governments around the world under a new program aimed at securing critical infrastructure and government assets from hacker attacks. The program, codenamed Omega, features a 'Defensive Information Sharing Program' that will offer government entities at the national level technical information on vulnerabilities that are being updated in their products." There's a stream the bad guys would dearly love to tap into.
This initiative is much too lame to warrant being called Omega.
The government never reads the documents that cross their desk. They just see what their constiucorps want and vote yea or ney.
"A person is smart. People are dumb, panicky dangerous animals and you know it." - K
As every black hat knows: you will not need to compromise the software. You just have to compromise one of the people working for the government in question.
If it's 3 days advance notice on patches like Microsoft's biggest customers get this is no big deal. If it's "Here are details on a vulnerability that we might patch next year with service pack 16", I'm afraid, very afraid.