{"id":94807,"date":"2014-01-15T12:20:12","date_gmt":"2014-01-15T10:20:12","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=94807"},"modified":"2014-01-15T12:40:52","modified_gmt":"2014-01-15T10:40:52","slug":"e-toll-security-hole-dont-shoot-the-messenger","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/94807-e-toll-security-hole-dont-shoot-the-messenger.html","title":{"rendered":"E-toll security hole: don\u2019t shoot the messenger"},"content":{"rendered":"<p>Organisations such as Sanral and the City of Joburg (<a title=\"CoJ\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/555699-City-of-Joburg\">CoJ<\/a>) could stand to learn from companies such as <a title=\"Microsoft\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/211580-Microsoft\">Microsoft<\/a>, <a title=\"Google\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/314567-Google\">Google<\/a>, and <a title=\"Facebook\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/348566-Facebook\">Facebook<\/a> when it comes to handling the disclosure of security flaws.<\/p>\n<p>That\u2019s the view of <a title=\"Dominic White\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/530068-Dominic-White\">Dominic White<\/a>, chief technology officer at <a title=\"Sensepost\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/313979-SensePost\">Sensepost<\/a>, an information security service provider.<\/p>\n<p>In the last few months security holes were uncovered in a number of prominent websites, including those of <a title=\"Vodacom\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/227063-Vodacom\">Vodacom<\/a>, <a title=\"Cell C\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/213919-Cell-C\">Cell C<\/a>, CoJ, and <a title=\"Sanral\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/372008-SANRAL\">Sanral<\/a>\u2019s E-toll site.<\/p>\n<p>While Vodacom and Cell C thanked the individuals for reporting the issue, the CoJ and Sanral responded by decrying the disclosures as cyber-attacks and threatening legal action against those responsible.<\/p>\n<div id=\"attachment_84933\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-84933\" class=\"size-full wp-image-84933\" alt=\"City of Joburg invoice screensho\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/08\/City-of-Joburg-invoice-screenshot-on-21-August.jpg\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/08\/City-of-Joburg-invoice-screenshot-on-21-August.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/08\/City-of-Joburg-invoice-screenshot-on-21-August-250x166.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><p id=\"caption-attachment-84933\" class=\"wp-caption-text\">City of Joburg invoice screenshot<\/p><\/div>\n<h3 class=\"my-4\">Full disclosure<\/h3>\n<p>White said that although the issue has been hotly debated for decades, responding in the way Sanral did is problematic because disclosing a vulnerability with an exploit is not the same as using the exploit for criminal purposes.<\/p>\n<p>\u201cFor example, if you figure out how to unlock a car and tell people, that\u2019s not the same as using the trick to steal cars,\u201d White said.<\/p>\n<p>It could also be argued that the efforts of \u201cMoe1\u201d, the person who disclosed the bug in the E-toll website, were intended to (and resulted in) making the eTolls website safer, White said.<\/p>\n<p>\u201cSanral was made aware of the flaw, with enough information to fix it, and were given a large incentive to do so rapidly by the publicity,\u201d White said.<\/p>\n<p>\u201cThis type of disclosure is known as \u2018full disclosure\u2019.\u201d<\/p>\n<h3 class=\"my-4\">Responsibility, culpability, liability, and all the other -ilities<\/h3>\n<p>Laying blame for the existence of the flaw at the feet of the person who found and disclosed it is simply illogical, White argued.<\/p>\n<p>\u201cThe responsibility for the original vulnerability clearly belongs to the developer who wrote the code, and can\u2019t lie with the vulnerability researcher who couldn\u2019t have had access to the code,\u201d White said.<\/p>\n<p>\u201cHowever, all code has bugs, and it could be further argued that the responsibility for the flaw lies with whoever was responsible for security during development,\u201d he continued.<\/p>\n<p>This does not mean that security researchers that disclose vulnerabilities don\u2019t have responsibilities, though.<\/p>\n<p>There can be consequences depending on how a vulnerability is disclosed, White said, and responsibility for those consequences can be attributed to the researcher.<\/p>\n<p>\u201cThat\u2019s usually where people get confused,\u201d White said.<\/p>\n<p>\u201cIn short, the site developers are responsible for the flaw, and the bug finder is responsible for fall out due to the way in which they disclosed the flaw,\u201d White said. \u201cHow responsible is not something our industry or South African law have clear guidance on just yet.\u201d<\/p>\n<h3 class=\"my-4\">\u201cResponsible disclosure\u201d<\/h3>\n<p>Since the person disclosing a vulnerability may be held responsible for the potential fallout, it raises the question: <em>how should vulnerabilities be disclosed?<\/em><\/p>\n<p>Asked about the industry buzz-phrase \u201cresponsible disclosure\u201d, White said that the term is typically used when a vulnerability researcher works with the owner of the affected software to fix the flaw in private.<\/p>\n<p>Only when the fix has been applied does the researcher release their findings.<\/p>\n<p>\u201cIt\u2019s a bit of a weasel term because it implies anything else is \u2018irresponsible\u2019 when it isn\u2019t clear that collaborating with the vendor is always the best method,\u201d White said.<\/p>\n<p>He said that the preferred term nowadays is <em>coordinated disclosure<\/em>.<\/p>\n<div id=\"attachment_94476\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-94476\" class=\"size-full wp-image-94476\" alt=\"E-toll website\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/01\/E-toll-website.jpg\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/01\/E-toll-website.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2014\/01\/E-toll-website-250x166.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><p id=\"caption-attachment-94476\" class=\"wp-caption-text\">E-toll website<\/p><\/div>\n<h3 class=\"my-4\">Coordinated vs full disclosure<\/h3>\n<p>White said that the arguments for coordinated disclosure are that risks are minimised since the public only finds out about the vulnerability after it is fixed.<\/p>\n<p>The arguments against it are that vendors have limited incentives to fix the flaw (or less pressure to). While the vendor takes its time to fix the flaw, others with more malicious intent may have already found it and started abusing it.<\/p>\n<p>\u201cTruthfully, this risk isn\u2019t measurable, and it isn\u2019t clear which approach works the best in general,\u201d White said.<\/p>\n<p>White said that a useful guideline is if a company has a security reporting page with guidelines for submitting vulnerabilities, it is worth at least trying coordinated disclosure first.<\/p>\n<p>\u201cIf that fails, then go the other route,\u201d White said.<\/p>\n<p>In the case of the Sanral website vulnerability, White said he doesn\u2019t know whether Moe1 tried to contact Sanral, but he added that he is also not sure that one approach would have had less risk overall than the other.<\/p>\n<h3 class=\"my-4\">What should Sanral do?<\/h3>\n<p>\u201cIf you have security researchers publishing vulnerabilities without contacting you, then you have a problem that won\u2019t be fixed by going after the researchers,\u201d White said.<\/p>\n<p>\u201cMicrosoft learned this lesson many years ago.\u201d<\/p>\n<p>White said that the solution is to become responsive to security issues, publish guidelines and contacts for reporting bugs, and have the right people respond to those requests.<\/p>\n<p>\u201cYou could even take it a step further and engage in bug bounty programmes like Google, Facebook, Microsoft, Mozilla and many others have done,\u201d White said.<\/p>\n<p>The least such programmes offer vulnerability researchers who report flaws is fame, and in many cases they also offer money.<\/p>\n<p>White said that this offers incentives that the reporting be done in a method preferable to the company, while simultaneously encouraging that flaws are found and reported rather than \u201cbad guys\u201d finding and exploiting them.<\/p>\n<h3 id=\"related\">More SA information security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94614-website-security-flaws-in-sa-shooting-the-messenger.html\"><strong>Website security flaws in SA \u2013 shooting the messenger<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94554-e-toll-website-flaw-a-cyber-attack-sanral.html\"><strong>E-toll website flaw a cyber-attack: Sanral<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94332-big-cell-c-security-flaw-uncovered.html\"><strong>Big Cell C security flaw uncovered<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/94234-my-vodacom-security-flaw-exposes-subscriber-details.html\"><strong>My Vodacom security flaw exposes subscriber details<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/93533-city-of-joburg-website-hacking-case-update.html\"><strong>City of Joburg website \u201chacking\u201d case update<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threatening legal action against people who discover and disclose security vulnerabilities is not helpful, according to an information security professional<\/p>\n","protected":false},"author":15,"featured_media":94560,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[9994,23159,6525,35,19544,23072],"class_list":["post-94807","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-city-of-joburg","tag-dominic-white","tag-e-toll","tag-headline","tag-sensepost","tag-south-african-national-roads-agency-limited-sanral"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/94807"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=94807"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/94807\/revisions"}],"predecessor-version":[{"id":94843,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/94807\/revisions\/94843"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/94560"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=94807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=94807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=94807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}