GDI.Foundation   

A safer Internet for everybody & everywhere 

    Blog​ : GFCE 2016 (​ Hungary)​    

    Global approach: Responsible Disclosure, Hacking and Cross Border  cooperation/ initiatives.    On the 23th of march 2016 we were honoured to be invited to tell about our work at GFCE  2016. With this blog we want to share the experience we had as ethical hackers and to keep  you updated what’s been achieved and further actions taken.      So what’s ​ GFCE​  all about?​  This was t​ he first meeting in Budapest to bring together  professionals from a range of countries,  private sector, academia and tech community to share  lessons learned, good practices and challenges in understanding responsible disclosure or  coordinated vulnerability disclosure policies and the broader topic of ethical hacking (​ program​ ).   

With other words: to make the Internet safer for all of us. And that’s pretty cool.     

Lesson Learned and future challenges  During the conference the “ lesson learned”  and issues were exchanged and made us think how  GDI.Foundation we can help in the next challenges:    ❖ Who to report the Responsible Disclosure when more parties and countries are  involved?    A example was the hacking of the software of a car. Do you send the RD to the car factory, the  company of the software or the company that installed the software & data. This also raise the question  what if the driver doesn’t wait for the necessary update of software, starts driving and has an accident  a/o causes an accident.     

❖ How to involve ethical hackers in controls (e.g. testing) and how to reward?  Is money an option and how much is reasonable. Or is recognition in “​ Hall of Fame​ ” more worth for the  ethical hacker. And what is the benefit of a bug bounty program and how much to pay?  It seems that in  1 

the private sector they all have a different approach and depends on the business. For example, a  company stopped with the bug bounty programs because it didn’t  have added value at a certain point in  time (lot of false positives and low risk vulnerabilities). However another company uses the bug bounties  and gives high rewards with a maximum. The question how to involve ethical hackers/ persons that  send a RD and rewarding them is still an open question.    

❖ How to make sure that the research information/ RD is only known to them who  needs to know?  Especially in the case of a found vulnerability that is applicable for more organisations and countries it’s  hard to know who “ needs to know” and need to be informed. Another challenge is who and when to  bring out the information in the open (news). Communication, timing and a central coordination is  probably needed to limit potential damages. 

  ❖ Is a specific law needed about ethical hacking & Responsible Disclosure?  Every country has got his own regulation, law and culture. Despite the differences everybody felt that  there is a lack between ethical hacking, RD’s and law but seemed not willing to prosecute an ethical  hacker as long as the intention is to help. They all commit to the manifest and are taken steps to involve  the lawmakers in this process.      As ethical hacker we were able to show that over the last 17 years Victor has reported more than 4.700  Responsible Disclosures worldwide and has never been prosecuted by any government a/o  organisation. We use the guideline Responsible Disclosure of the Dutch NCSC to backup us in the do’s  and dont’s when we ever get confronted in court. Besides that we started a foundation to safeguard our  intention. However we have to make sure our work is auditable and organisations can trust as in our  intention and work despite the (lack of) law or regulation. This is an action for me, as ex­auditor, to be “in  control” of. 

  ❖ What to do with Responsible Disclosures in outsourcing and (legacy) contracts?  Outsourcing IT activities and services is quite common in the ICT environment. However nowadays we  all get confronted with vulnerabilities and the financial cost of fixing the vulnerability. In the worst  scenario the vulnerability is not fixed because it’s not financially covered between the parties and the  vulnerability is wide broad known. Maybe splitting the costs is for now the best option for the community  (..).   

  ❖ Does it stop after fixing a Responsible Disclosure or is it the beginning?  The chance of more vulnerabilities and receiving Responsible Disclosures is hudge. Not alone the  complexity of ICT, the legacy but also the growth of connectivity of things and “time to market” is putting  great pressure on security, testing and the profits of organisations. Getting a Responsible Disclosure  has not only got  impact on those who receive them in solving the vulnerability but also needs a learning  process to minimize vulnerabilities in the future.     What’s the cause of the vulnerability, do we have to adjust the change management process, is our  testing outdated and does it need to be adjusted? Till now I haven’t seen a process or role in the  organisation who is accountable for this issue and that can be shared with others to learn. However for  now, the next generation and to prevent a free and open Internet this is a fundamentally aspect.  Learning and sharing the knowledge is essential.  

     

 



Our experience  It was good to meet so many people over the world who share the same goal as we do,  achieving a safer Internet for all of us and next generation. The  private sector, academia and governments really put effort to  make the meeting into a success. The openness of all the actors  about their experience about responsible disclosure, bug bounties  and ethical hacking also gave us insight information about their  views and impact of Responsible Disclosure.          In the 3 days that we were there, Victor was continuously working to  help others and send out a couple of RD’s (even at 3 in the  morning). In the presentation it gave us the opportunity to actually  show a RD concerning a organisation in Hungary. This specifically  RD was send in the morning and was fixed within one hour. And  that’s fast!          What really helped us is the openly spoken back up for our work (e.g. CISCO,  NCSC, NCSIR Romania, Belgium and others) and the need of our work in the  total spectrum of security and vulnerabilities.          Meeting everybody, the appreciation and backup we’ve got about the work we have done so far  is encouraging us to continue and hope to be a part in it. Besides that it was pretty cool to get a  signed book of A. Friedman. Especially written for GDI. Foundation. I now I feel obliged to read  the all those 350 pages. I hope it’s got a summary…:)    

 

 

         3 

GDI.Foundation and next steps GFCE    After the presentation we got several invitations and shared information how we can help each  other (​ workshop, presentations, procedures etc.​ ). We hope that this initiatives are really going  to happen and we will be able to share our knowledge and start a community in sharing the same  interest and information in what’s needed for now and the next generation.  

  We honestly hope and think our presentation about our foundation and the work we have done  so far will to make the next steps and we are looking forward to help in accomplishing these  steps.    We especially want to thank Hungary, the NCSC and the Dutch ministry of Foreign Affairs​  who  made it possible for us to come over and tell our story. But overall we want to thank all the  members of GFCE 2016, the openness to share lessons learned and the experiences that has  been shared!      If you’ve any suggestions, advice etc. after reading this blog please let us know. 

 

http://www.thegfce.com/news/news/2016/03/21/announcement­dakar­meeting 



Blog GFCE 2016_Responsible Disclosure and Lessons ...

Blog GFCE 2016_Responsible Disclosure and Lessons Learned_29032016.pdf. Blog GFCE 2016_Responsible Disclosure and Lessons Learned_29032016.

2MB Sizes 1 Downloads 192 Views

Recommend Documents

financial disclosure
Oct 3, 2010 - to cash (6%), this fund is comprised of insurance company contracts .... Apple Ipad - a gift celebrating my departure as President and CEO of ...

financial disclosure
Oct 3, 2010 - to the best ofmvknowledge. • n~t..~ T>mr ... Examples IDoe_Jone~ ~SE1ith,_H~m:tow'1;, Sta~e__ ... Federal Reserve Bank of San Francisco. 3.

D Disclosure and Transparency.pdf
edocuments/generalinformationsheet.pdf. D.1.2 Does the company ... Sources: Company Website ... The Company is still planning on creating an annual report.

Information Disclosure, Real Investment, and ...
May 15, 2017 - Haas School of Business, ... disclosures if (i) the firm's current assets in place are small relative to its future growth oppor- ... quality of accounting disclosures fixed, we directly compare welfare of the firm's ..... To measure t

disclosure and authorization agreement regarding consumer reports
whole or in part on the information contained in the consumer report, you will be provided a copy of the report, the name, address and telephone number of the ...

disclosure and authorization agreement regarding consumer reports
You also agree that a fax or photocopy of this authorization with your signature be accepted with the same authority as the original. READ, ACKNOWLEDGED ...

competition and disclosure - Wiley Online Library
There are many laws that require sellers to disclose private information ... nutrition label. Similar legislation exists in the European Union1 and elsewhere. Prior to the introduction of these laws, labeling was voluntary. There are many other ... Ð

Caracal disclosure album
And enjoy the.80523364682 - Download Caracal disclosurealbum.Completelog ... The Graduate.Vmware workstation v7.1.3.80523364682 ... November 9 pdf.

Caracal disclosure album
Young jeezy .torrent.C. m. owens.Assparadesophie nikki.Using afunneland filter paper, placea Caracal disclosurealbumfromeach test tube who let the dogs ... Ashley sinclair i have.259192770885868.November 9 pdf.Download Caracal disclosurealbum- Heroes

Board and auditor interlocks and voluntary disclosure in ...
cross-sectional data from 149 non-financial companies listed on the Dutch ... big audit firms since they differently induce firms to voluntarily disclose .... information on over 11 million public and private companies in 41 European countries.

monetize-your-blog-make-initiate-a-blog-furthermore-monetize ...
Connect more apps... Try one of the apps below to open or edit this item. monetize-your-blog-make-initiate-a-blog-furthermore-monetize-1499499132653.pdf.

www.personaldevelopmentbooks.net/Blog Free Articles and eBooks ...
lookout, then, at every point, to see that you build into the foundation only ... Keep your mind free, then, to work upon the subject-matter of the lecture. Debate ...

Disclosure Statement Volunteers.pdf
I understand that if the person responsible for employment decisions or the administrator of a program,. activity or service has a reasonable belief that I was ...

SPONSORED BLOG POST, DISPLAY, AND NEWSLETTER ADS ...
SPONSORED BLOG POST, DISPLAY, AND NEWSLETTER ADS RATE CARD.pdf. SPONSORED BLOG POST, DISPLAY, AND NEWSLETTER ADS RATE ...

Professional Disclosure Statement.pdf
includes couples counseling, family and blended family counseling, adolescent. counseling, crisis counseling, divorce adjustment group work and parenting ...

Corporate Disclosure Statement.pdf
Sign in. Loading… Whoops! There was a problem loading more pages. Retrying... Whoops! There was a problem previewing this document. Retrying.Missing:

When mandatory disclosure hurts: Expert advice and ...
bDepartment of Economics, University of California at Berkeley, 549 Evans Hall, ..... Our first lemma describes how an expert's ranking of two actions depends on ...

doc-Introductory note to Disclosure of Project and Contract Information ...
domain with open access to the public free of charge; and second, reactive disclosure2. of specific. information where information is disclosed on request by the public on payment of charges associated. with the cost of providing the information. Vic

Information Acquisition and Strategic Disclosure in ...
Suppose firms have beliefs consistent with the disclosure rule δS, as defined in (20),. i.e. (21), (22), and (23). If a firm discloses θ, both firms supply xf(θ). If no firm disclosed information, i.e. (D1,D2)=(0,0), and firm i received signal Θi

AUTHORIZATION FOR USE AND/OR DISCLOSURE OF INFORMATION
The use and distribution of this form is limited to employees of public school agencies within the North Region Special Education Local Plan Area (SELPA).

Blog docentes.pdf
Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. Blog docentes.pdf. Blog docentes.pdf. Open. Extract. Open with.