NTIA to seek consensus on security-vulnerability disclosures
The National Telecommunications and Information Administration (NTIA) hopes to gather security researchers, software vendors and other interested people and reach consensus on the sticky topic of how to disclose cybersecurity vulnerabilities. The first NTIA-hosted meeting will be Sept. 29 at the University of California, Berkeley, School of Law. Registration is open to all who want to participate, and the meeting will also be webcast, NTIA said. Some researchers' public disclosures of previously unknown vulnerabilities has been controversial, with some software vendors complaining the information can help hackers compromise systems before they can be patched. Many researchers believe that public disclosure gives software vendors an incentive to issue patches. But the NTIA sees potential for a consensus to develop, with strong security as the goal, said deputy assistant secretary Angela Simpson. . Participants in the process, not the NTIA, will determine the outcome, she added. "The community holds the pen."
NTIA to seek consensus on security-vulnerability disclosures