HomeSecurityYahoo: security team will disclose vulnerabilities 90 days after...

Yahoo: security team will disclose vulnerabilities 90 days after finding them

Yahoo 's security team said that any vulnerabilities discovered in penetration tests will be disclosed to the public after a period of 90 days.Yahoo-Security-Team-to-Reveal-Vulnerabilities-90-Days-after-Finding-Them

One of the team's responsibilities is to assess the security level of software written by Yahoo by testing both the code and that of third-party providers and that has been integrated into the service provided by the company.

The group calls itself Yahoo Paranoids, and led by Mr. Chris Rohlf, carries out attacks against the infrastructure in order to find new weaknesses that a malicious person can exploit.

“This process helps us uncover vulnerabilities, not just in software Yahoo has written, but in open-source and commercial products we use on our network,” Mr. Rohlf wrote Tuesday in a Tumblr post.

The new team's job is to ensure that when unknown vulnerabilities in the code (also known as zero-day vulnerabilities) are discovered, they are immediately fixed by the experts, who will also inform other organizations that may be affected by the problem, as well as the US-CERT (Computer Emergency Readiness Team).

While 90 days may seem like a short amount of time for the code developer to fix a problem, a longer timeframe will increase the risk to users, giving cybercriminals the opportunity to find the flaw for themselves and exploit it.

However, Mr. Rohlf states that: “We reserve the right to extend or shorten this timeline based on circumstances such as already exploitable vulnerabilities, or the existence of known threats.”.

Cybercriminals are usually successful because they are constantly looking for zero-days, that is, vulnerabilities that are not known and that by the time they are known, the victim or victims will have been compromised. Yahoo believes it is adopting a new dynamic stance against this practice that covers not only its own code but also the code of third parties it collaborates with.

Whether to disclose a vulnerability after 90 days depends on many factors, including the difficulty of addressing the flaw, which can sometimes take longer to release a patch. However, if there has been little or no progress since the vulnerability was discovered, Yahoo reserves the right to disclose it in order to force companies to take immediate defensive measures or prepare a patch.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS