eWeek Security Watch
Advertisement
Advertisement
April 21, 2008 2:10 PM

Microsoft Picks New Song for Hacker Slow Dance



Microsoft has chosen a new song to continue its public slow dance with the white hat hacking community: online properties like *.microsoft.com, *.msn.com and *.live.com.

According to Dan Goodin reporting from Toorcon Seattle, Microsoft security strategist Katie Moussouris pledged that the software vendor will not sue or press charges against ethical hackers who responsibly find--and report--vulnerabilities in its online services.

The embrace of the hackers is not entirely new--Microsoft has been addressing this issue in hacker forums--but the public offer of immunity for hackers who hunt for holes in its Web properties is seen as significant.

In a nutshell, it's not legal to hack into Web sites--see this post by Veracode's Chris Wysopal--and many SAAS (software as a service) companies frown on attempts to attack its servers with impunity.

But, as Microsoft's Moussouris points out, companies should be thankful when researchers help pinpoint weaknesses in online systems.

"The philosophy here is if someone is being nice enough to point out your fly is down, they're really doing you a favor and you should thank them rather than calling the cops and saying you're a pervert."

Microsoft has set up a special Web site to acknowledge and thank hackers who report online vulnerabilities. Since July 2007, 48 hackers have been credited with finding Web site bugs.

* Photo credit: jem (Creative Commons 2.0)

Create, Communicate, Collaborate with IT Professionals at Ziff Davis Enterprise IT Link

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/13357

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise