Menu
OpenSSL warns vendors against using vulnerability info for marketing

OpenSSL warns vendors against using vulnerability info for marketing

Vulnerability information will be closely held until patches are ready, the OpenSSL Project said

Security advisories for OpenSSL should not be used for competitive advantage, according to the development project behind the widely used cryptography component.

The warning comes from the OpenSSL Project, which has published for the first time guidelines for how it internally handles security problems, part of an ongoing effort to strengthen the project following the Heartbleed security scare in April.

High severity issues such as remote code execution vulnerabilities will be kept private within OpenSSL's development team, ideally for no longer than a month until a new release is ready.

If an update is planned, a notification will be released on the openssl-announce email list, but "no further information about the issues will be given," it said.

Some organizations that develop a general purpose OS that includes OpenSSL will be prenotified with more details about the patches in order to have a few days to prepare. But the OpenSSL Project warned that the more people that are notified in advance, "the higher the likelihood that a leak will occur."

"We may withdraw notifying individual organizations from future prenotifications if they leak issues before they are public or over time do not add value (value can be added by providing feedback, corrections, test results, etc.)," it wrote.

If information on a vulnerability leaks, it makes it more likely that attackers may be able to figure out the software flaw and launch attacks before software products are patched.

The OpenSSL Project also advised that "it is not acceptable for organizations to use advance notice in marketing as a competitive advantage. It objects, for example, to marketing claims such as 'if you had bought our product/used our service you would have been protected a week ago.'

OpenSSL has been undergoing an intense code review since the Heartbleed vulnerability was discovered in April. The flaw affected tens of thousands of websites across the Internet and many software applications.

OpenSSL is a cryptographic library that enables SSL (Secure Sockets Layer) or TLS (Transport Security Layer) encryption. Most websites use either SSL or TLS, which is indicated in browsers with a padlock symbol.

Exploiting Heartbleed could allow attackers to extract private SSL keys from a server and potentially decrypt traffic. In some cases, the flaw cause the server to leak user credentials.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Or
Error: Please check your email address.

Tags securityopen sourcesoftwareOpenSSL Project

Featured

Slideshows

Bumper channel crowd kicks off first After Hours of 2018

Bumper channel crowd kicks off first After Hours of 2018

After Hours made a welcome return to the channel social calendar with a bumper crowd of partners, distributors and vendors descending on The Jefferson in Auckland to kick-start 2018. Photos by Gino Demeer.

Bumper channel crowd kicks off first After Hours of 2018
Looking back at the top 15 M&A deals in NZ during 2017

Looking back at the top 15 M&A deals in NZ during 2017

In 2017, merger and acquisitions fever reached new heights in New Zealand, with a host of big name deals dominating the headlines. Reseller News recaps the most important transactions of the Kiwi channel during the past 12 months.

Looking back at the top 15 M&A deals in NZ during 2017
Kiwi channel closes 2017 with After Hours

Kiwi channel closes 2017 with After Hours

The channel in New Zealand came together to celebrate the close of 2017, as the final After Hours played out in front of a bumper Auckland crowd.

Kiwi channel closes 2017 with After Hours
Show Comments