<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Thu, 14 Jun 2007 00:31:09 -0000</lastBuildDate><item><title>Re: Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://www.matasano.com/log/878/security-boat-anchors-3rd-party-productslibraries/#comment-2322772</link><description>Tom:&lt;br&gt;&lt;br&gt;We could start with a single question:&lt;br&gt;&lt;br&gt;"Do you mandate any sort of security activity as part of your product development lifecycle?"&lt;br&gt;&lt;br&gt;There's a follow-on, which is "please explain."&lt;br&gt;&lt;br&gt;Since 90% of the vendors don't make it to the follow-on (yet), considerations of comparisons between explanations are secondary.  But I'm happy to &lt;a href="http://www.homeport.org/~adam/review.html" rel="nofollow"&gt;go there&lt;/a&gt; at length.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Adam</dc:creator><pubDate>Thu, 14 Jun 2007 00:31:09 -0000</pubDate></item><item><title>Re: Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://www.matasano.com/log/878/security-boat-anchors-3rd-party-productslibraries/#comment-2322771</link><description>I came across this when looking for something else:&lt;br&gt;&lt;a href="http://www.cigital.com/labs/reliability/certification.php" rel="nofollow"&gt;http://www.cigital.com/labs/reliability/certifi...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dre</dc:creator><pubDate>Wed, 13 Jun 2007 18:12:33 -0000</pubDate></item><item><title>Re: Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://www.matasano.com/log/878/security-boat-anchors-3rd-party-productslibraries/#comment-2322770</link><description>Adam: what's a short questionairre a security-savvy front-line developer could use to quiz a third-party partner, and reasonably expect to get a meaningful response on?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 13 Jun 2007 15:35:28 -0000</pubDate></item><item><title>Re: Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://www.matasano.com/log/878/security-boat-anchors-3rd-party-productslibraries/#comment-2322769</link><description>What about asking about their development practices?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Adam</dc:creator><pubDate>Wed, 13 Jun 2007 12:15:48 -0000</pubDate></item><item><title>Re: Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://www.matasano.com/log/878/security-boat-anchors-3rd-party-productslibraries/#comment-2322768</link><description>If you as a developer find a need to plug in one of a shortlist of open source projects to complete a task, consider that the larger and more responsive the project's community the:&lt;br&gt;&lt;br&gt;A. More likely code audits will be done, and present vulns fixed.&lt;br&gt;B. The quicker any bugs from step A will be patched.&lt;br&gt;C. The more noise will be made about any vulns found in step A, so the more likely you will hear about them.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Rhys Kidd</dc:creator><pubDate>Tue, 12 Jun 2007 08:38:45 -0000</pubDate></item><item><title>Re: Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://www.matasano.com/log/878/security-boat-anchors-3rd-party-productslibraries/#comment-2322767</link><description>ahah good luck! now, seriously, what about all those that have embedded 3rd party libraries and don't disclose it (and some may not even _know_ they do). some plausible examples: zlib, libpng, xerces, openssl (or portions of it), multiple audio/video codecs, etc. Some of them may have been "namespace-cosmetized"  and statically linked into the product just to get it out the door in time several release cycles (years) ago and now nobody even knows the code is there...implausible you say?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ivan</dc:creator><pubDate>Tue, 12 Jun 2007 02:19:22 -0000</pubDate></item><item><title>Re: Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://www.matasano.com/log/878/security-boat-anchors-3rd-party-productslibraries/#comment-2322766</link><description>Here in the Middle East, I’ve seen vendors of certain Applications running really old versions of 3rd party software which are riddled with vulnerabilities.  I get called in to conduct an application security assessment and I usually include these findings in addition to the application audit itself.&lt;br&gt;  &lt;br&gt;The problem I see is when the customer has already selected the product and deployed it without proper guidance in the beginning.  Richard makes a valid point that if it is a contractual obligation, then you’re covered to a certain extent, but how do you solve it after it has been put into place?&lt;br&gt;&lt;br&gt;One of my customers has been waiting for a fix to a 3rd party product for over 6 months.  In my case, it has taken countless extra days (at no cost) for me to sit with the vendor and try to explain why these patches need to be applied only to receive the response that the patches will break the functionality of the application.  When I ask for technical proof of this or a demo in a staging environment, I never receive it.  At this point, I offer the customer an addendum to my contract which lets me act on behalf of the customer to work out the problem technically with the vendor.  In most cases, the customer will not want to spend the additional amount, will concede and take on the responsibility as an “acceptable risk”.  These are banks.  I don’t think people take security seriously here.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Sheran</dc:creator><pubDate>Tue, 12 Jun 2007 01:49:29 -0000</pubDate></item><item><title>Re: Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://www.matasano.com/log/878/security-boat-anchors-3rd-party-productslibraries/#comment-2322765</link><description>As a customer of vendors who embed 3rd party products and libraries, we're leaning towards requiring security patches for the 3rd party components be applied and an updated version of the package available to us within a short, reasonable interval.  Eventually, a vendor's failure to provide such an assurance will be enough to kill their proposal.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Richard Johnson</dc:creator><pubDate>Mon, 11 Jun 2007 19:40:47 -0000</pubDate></item><item><title>Re: Security Boat Anchors: 3rd Party Products/Libraries</title><link>http://www.matasano.com/log/878/security-boat-anchors-3rd-party-productslibraries/#comment-2322764</link><description>secure software contract annexes backed by open industry certifications/review (owasp, mitre, wasc, sans-ssi, et al)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dre</dc:creator><pubDate>Mon, 11 Jun 2007 17:05:37 -0000</pubDate></item></channel></rss>