Security through Transparency – How We Disclose Security Vulnerabilities

We founded aramido with the vision of making the use of information technology secure for everyone. To achieve this goal, several levers must be pulled. One of the most effective is helping companies that produce software or operate it for a large number of employees and customers to build security into their products from the ground up according to the principles of Security By Design . One of the most effective measures for finding vulnerabilities in IT systems and applications is penetration testing . In this process, we specifically and on behalf of our customers examine IT systems for vulnerabilities and provide recommendations on how they can be remediated. But what happens to vulnerabilities that we find outside of specific customer assignments? In this case, we follow an industry-wide recognized approach.

How to Handle Discovered Security Vulnerabilities

As we already described in our article on secure software updates , it is nearly impossible to develop error-free software due to the complexity of software. However, if errors are found later, they should be remediated by the software manufacturer, especially if they affect security. When you deal professionally with the security of software and specifically web applications as we do, you regularly notice security vulnerabilities. These security vulnerabilities can then be:

  1. reported to the person responsible for the software, or
  2. not reported.

Option two, not reporting knowledge of a security vulnerability, exploiting it yourself, or selling it, is out of the question for us for ethical reasons. However, it can never be ruled out that someone else has already discovered the security vulnerability and is actively exploiting it. Furthermore, concealing security vulnerabilities would contradict our mission to make IT secure.

This leaves the option of reporting the security vulnerability to the person responsible for the software, so that they can remediate the vulnerability. There are the following approaches:

  1. Full Disclosure
  2. Non Disclosure
  3. Coordinated Disclosure

Full Disclosure – Publish Security Vulnerabilities Immediately

Full Disclosure describes the approach of publishing security vulnerabilities immediately and completely without waiting for a patch from the manufacturer. In favor of this approach is the fact that users learn about security vulnerabilities as quickly as possible in order to initiate their own protective measures. As already noted, the security vulnerability could have already been discovered and exploited by other people. Nevertheless, it can be critical to publish a security vulnerability for which no patch is yet available, as users may then be specifically endangered. If the vulnerability has not been exploited so far, the probability of this increases at least significantly – after all, the knowledge is now available to malicious hackers. A popular way to publish security vulnerabilities according to the Full Disclosure principle is the announcement via the Full Disclosure mailing list.

Non Disclosure – Do Not Publish Security Vulnerabilities

The opposite of full disclosure is the non-publication of vulnerabilities. Instead, these are reported confidentially to the manufacturer. It is then up to them whether and when they provide a patch for the security vulnerability. The justification for not publishing security vulnerabilities is that one does not want to make the work of malicious hackers easier. This is countered by the fact that attackers often discover the security vulnerabilities themselves through other means. Concealing security vulnerabilities would thus lead to an information imbalance between attackers and users. Furthermore, critics of a Non Disclosure Policy argue that manufacturers only give security vulnerabilities the appropriate attention under the pressure of publication, that the general public can learn from the errors, and that similar errors can thus be avoided.

Coordinated Disclosure – Publish Security Vulnerabilities Responsibly

Coordinated disclosure is often also referred to as responsible disclosure. It is the middle ground between Non Disclosure and Full Disclosure. Here, the manufacturer is first informed about a security vulnerability in a confidential manner. They are given a reasonable period of time to remediate the security vulnerability. Details of the vulnerability are only published after the publication of a security update or the expiration of the set deadline. This is intended to minimize the risks for users: on the one hand, the probability of exploiting security vulnerabilities through publication without a simultaneous patch should be reduced, and on the other hand, users should be warned about vulnerabilities in the software they use. A well-known project that works according to this principle is Google Project Zero. This consists of a group of security researchers who, on behalf of Google, search for unknown security vulnerabilities (so-called Zero Days) in various applications not developed by Google and publish them using the Coordinated Disclosure process, usually with a deadline of 90 days. But more and more large providers, such as Facebook or Mozilla, organize the responsible disclosure of vulnerabilities in their products themselves via bug bounty programs.

How does aramido handle found security vulnerabilities?

After weighing the arguments described above for the different disclosure variants, aramido has decided to disclose security vulnerabilities responsibly according to the following procedure:

Procedure for the responsible disclosure of security vulnerabilities (Responsible Disclosure Policy)

Nearly every IT system has errors. These errors are often discovered only over time. If these errors allow the confidentiality, integrity, or availability of the systems, the applications, or the data stored in them to be impaired, a security vulnerability exists. aramido GmbH sees it as its task to report security vulnerabilities to the manufacturers, operators, and users in a responsible manner.

Security vulnerabilities found by aramido GmbH are published according to the following procedure for responsible disclosure. Exceptions to this are vulnerabilities that are in the area of responsibility of a customer of aramido GmbH or are excluded from publication by other contractual agreements.

After a security vulnerability is found, the person responsible for the application or system is informed in a confidential manner. Information about the vulnerability and its exploitability is provided. After the vulnerability is remediated or at the latest after 45 days, regardless of the remediation status, it will be published on the aramido GmbH website. This procedure is deviated from only in justified exceptions and after weighing the impact on the general public.

If a security vulnerability is found by aramido, it could have already been found and exploited by other parties. Therefore, security vulnerabilities should be closed as quickly as possible. To protect the general public, the public should be informed about found security vulnerabilities. In this way, vulnerabilities can be remediated, lessons can be learned from mistakes, and behavior can be adjusted.

Under the category Security Advisories , you will find in the future security advisories that were found and disclosed by employees of aramido.

Armin Harbrecht

On 06.02.2017 in the category Security Advisories published.