Government Technology

Report: Zero-Day Exploits Catch Regulators' Attention



September 4, 2012 By

When thousands of Iran's centrifuges were remotely disabled, it set the nuclear facility back an estimated 18 months. The failures, which were discovered in 2010, were caused by a computer worm called Stuxnet, which was developed by U.S. and Israeli intelligence agencies taking advantage of security holes in Iran's computer networks. Stuxnet was effective because it used several “zero-day exploits,” security vulnerabilities unknown to the victim of the attack.

Zero-day exploits sell for thousands of dollars in the intelligence community and their power has caught the attention of some officials who want to regulate the exchange of such information, reported The Washington Post. Many software developers offer cash prizes to those who can reveal serious security flaws in their software, while other software makers have been less appreciative, even going so far as to sue the person revealing the flaw.

“It’s like trying to regulate guns,” said Richard Schaeffer Jr., a former senior cybersecurity official at the National Security Agency, reported the Post. “We’ve got so many gun laws on the books, and yet criminals still have guns. There will always be mean, wrong, illegitimate things that human beings do for a price. So instead of trying to regulate things away, we need to accept it’s a fact of life. And the question is, how do we coexist with it?”

To read in-depth about the world of zero-day exploits and those who wish to regulate them, visit the Washington Post.


You may use or reference this story with attribution and a link to
http://www.govtech.com/security/Zero-Day-Exploits-Catch-Regulator-Attention.html


| More

Comments

Add Your Comment

You are solely responsible for the content of your comments. We reserve the right to remove comments that are considered profane, vulgar, obscene, factually inaccurate, off-topic, or considered a personal attack.


Collaboration for the Public Sector



Collaborative Justice: Transforming Criminal Justice Services Through Unified Collaboration
This issue brief examines video collaboration in every stage of the human justice process, demonstrating how this technology can not only make services more efficient, affordable, and accessible.

Cloud-Based Services Accelerate Public Sector Adoption of Video Collaboration
Today, thanks to new cloud technologies and high-quality networks, mobile video services - which provide not only cost savings but which help governmental interactions become more efficient - are more feasible than ever before.

Modernization as a Service: Acquiring IT through Innovative Procurement

Five Ways Collaboration is Driving Government Performance

Mobile Video Collaboration: The New Business Reality