Re: cloud computing provider disclosures
Aaron Rainbolt opposes a cloud-provider disclosure idea, warning that public fixes fuel rapid exploits.
In an oss-security reply, Aaron Rainbolt argues against a proposed approach to cloud computing provider disclosures. He says providers already need a way to update their environments immediately because of the zero-day market. He also warns that once a fix is public, others may quickly build an exploit without knowing more about the underlying flaw. No specific vulnerability, vendor incident, or CVE is disclosed.
- Aaron Rainbolt replies on the oss-security list about cloud disclosures.
- He says providers must be able to update immediately because of zero-days.
- Public fixes can be turned into exploits without deeper vulnerability details.
Posted by Aaron Rainbolt on Oct 04 I don't really think I'm a frequent enough contributor here to have much say, nor do I run a cloud service, but I personally don't like this idea so much. Cloud providers have to have a robust method to update their world at any instant because the zero-day market is a thing, and because people sometimes see a fix go public and immediately come up with an exploit for the vuln it fixes without knowing anything more about the vuln....
This source does not provide full text. Read it at seclists.org.