Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

July 28, 2010 12:39 PM

Microsoft, Adobe Deepen Security Ties

Windows IT Pro
InstantDoc ID #125676
Rating: (15)

At the Black Hat security conference on Wednesday, Microsoft and Adobe announced they were dramatically expanding their relationship in order to better protect users against electronic threats. Now, Adobe will provide vulnerability information about its products via Microsoft's Active Protections Program (MAPP) to security solution vendors, as does Microsoft. Adobe is the first third party vendor to provide this crucial information, which will help security software makers more rapidly address new threats.

"Given the relative ubiquity of many of our products, Adobe has attracted increasing attention from attackers," Adobe senior director Brad Arkin said. "We are committed to our customers' security at every level and are excited to leverage MAPP as an important part of our overall product security initiative. MAPP is a great example of a tried and proven model giving an upper hand to a network of global defenders who all rally behind a shared purpose: protecting our mutual customers."

Microsoft launched MAPP in 2008 as a way to facilitate early vulnerability information sharing with its partners, and today there are over 65 companies participating in the program. In a briefing this week, Microsoft described MAPP as a "game changer that reduces the time for partners to develop responses to emerging security threats."

Previous to MAPP, security vendors would have to use publicly disclosed information about threats to reverse engineer fixes. It created a situation where Microsoft's Patch Tuesday was followed by "Exploit Wednesday," because it was far easier for hackers to exploit the just-announced vulnerabilities than it was for security vendors to respond to those vulnerabilities.

Now, with Adobe's participation, both Microsoft and Adobe will be providing security vendors with information about vulnerabilities before the fixes are made public. The goal is to end "Exploit Wednesdays" because the vendors' customers will already be protected.

Microsoft also talked up the latest security bugaboo at Black Hat--the debate between those who feel that security vulnerabilities should be disclosed immediately and without context and those, like Microsoft, which feel that there is a more responsible way to disclose this information. Microsoft is calling on the broader security community to move to a model of coordinated vulnerability disclosure and believes that everyone involved needs to accept some responsibility for how (and when) this information is communicated.

Microsoft didn't specifically address the recent impetus for this discussion, but let's just say that hundreds of millions of Windows users are currently at risk of being exploited by a "zero-day" vulnerability because the person who discovered it has different ideas around responsibility and disclosure. "We must work together to improve the security of the entire ecosystem," a Microsoft statement reads, "and, as always, making customer protection our highest priority."

Microsoft also announced an interesting new free security tool at Black Hat. The Enhanced Mitigation Experience Toolkit (EMET) provides newer security features--like DEP and ASLR--to older Microsoft platforms and applications, the company says. It will ship in August.

Related Content:

ARTICLE TOOLS

Comments
  • S
    2 years ago
    Jul 29, 2010

    The best way to prevent adobe security issues is for people to stop using the annoying PDF format for pointless things which requires people to download and use reader. PDF was never meant for what it is used today. HTML is sufficient.

    Second, flash needs to be fully sandboxed so it is not as easily exploitable.

    Third, companies should be made liable for failure to respond to security issues once they are raised to them and given proper time to fix them. While I fully disagree that the right thing to do is let an exploit into the wild without allowing the company to fix it, it is also true some of these companies are just plain lazy because they have no motivation to fix things. Liability may be the only thing that makes them respond quicker (hear that linksys?)

  • Roncerr
    2 years ago
    Jul 28, 2010

    So how does this affect us? Will Adobe fixes be on Windows Update or in the updates to Microsoft Security Essentials? Or do we still have to go to Adobe to check for updates separately? Do we still need to update Flash Player by first going to a special page on Adobe's site to download the latest version of their uninstall program to uninstall the current version, then go to yet another web page to download the new version of Flash and reboot a couple times in the process?

  • M
    2 years ago
    Jul 28, 2010

    It's about time both companies started talking to each other concerning security! Both MS & Adobe have been in the bad guys' cross-hairs for ages. Responsible vs full disclosure has been talked about for ages, and I don't think anyone has found the best solution yet.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.