InfoSecurity Magazine Posted By: Pete O'Hara 2/13/2001
The term "full disclosure" is marvelously ambiguous, and therein lies much of the problem. It essentially means to "widely disseminate as much information about system vulnerabilities and attack tools as possible so that potential victims are as knowledgeable as those who attack them." Admittedly, this concept has a certain appeal. But where does this "information" to disseminate come from?
Developments in human technology follow a consistent pattern: a basic researcher (of which there are precious few) discovers a new principle; an engineer (of which there are a few more) builds a tool that applies the principal; and non-specialists (there are a bunch of these) use the new tool. Long before the term "script-kiddie" came into vogue, a small core of gurus was recognized as responsible for discovering most security bugs. A larger group of skilled programmers then wrote programs to exploit these bugs, releasing them to the greater population of hacker-wannabes.
Having discovered that they can attract huge amounts of attention by throwing rocks at Windows, so-called security professionals are increasingly the ones fulfilling both the research and the application stages. Sadly, the shortest path to computer security fame seems to lie more in providing candy to children than in breakthroughs in dental hygiene. The concept of full disclosure is, indeed, ambiguous, serving as a politically correct shield behind which all manner of self-serving behavior can be justified. It's far too often used to rationalize shortsighted information releases that benefit the announcer to the detriment of the entire Internet community.