Secunia CSI 5.0
About us
Careers
Memberships
Newsroom
Contact us
Blog
News
Articles

Vendors still use the "legal" weapon

Get this blog as an RSS Feed
In these days, one would have believed that vendors have learned the lesson not to threaten with legal actions to withhold and suppress significant information about vulnerabilities in their products.
12:58 CET on the 6th December 2007
Entry written by Thomas Kristensen.

In these days, one would have believed that vendors have learned the lesson not to threaten with legal actions to withhold and suppress significant information about vulnerabilities in their products.

Well, nonetheless, Secunia just received a sequel of letters from Autonomy, likely not known to many, but it is the software company that supplies the "Swiss Army Knife" in handling and opening documents in well known software like IBM Lotus Notes and Symantec Mail Security.

First a little background information
The communication between Autonomy and their OEM customers regarding which versions of their KeyView software that fix given vulnerabilities has failed again and again. This has been a mess to sort out and Secunia has had to spent hours verifying what e.g. was fixed by IBM and what was fixed by Symantec - because apparently the versioning of the KeyView software is different whether used by Symantec, IBM, or others.

We've managed to figure this out and occasionally this has caused one of Autonomy's OEM customers to have unpatched publicly known vulnerabilities in their products. All thanks to Autonomy's apparent inability to co-ordinate the release of new vulnerability fixes with their customers.

Now, Autonomy has become fed up with handling all these vulnerabilities and believe that it is time to control what Secunia writes about. Autonomy wants Secunia to withhold information about the fact that vulnerability SA27835 in Keyview Lotus 1-2-3 File Viewer, which has been fixed by IBM, obviously also affects Autonomy's own versions 9.2 and 10.3 of KeyView.

According to Autonomy, publishing an advisory would be misleading and cause confusion because the issues already have been fixed; in fact, they believe that this would cause the public to believe that there are more issues in their product than is the case!

Now that is an interesting logic.

Sorry Autonomy, writing an advisory that states which vulnerabilities have been fixed and in which versions is in no way misleading or confusing - even for "historical" issues.

What is really interesting here is the fact that the Vulnerability Database services offered by Autonomy's own customers IBM and Symantec (ISS X-Force and Securityfocus respectively) still (at the time of publishing) don't show information about the fact that patches are available for the Lotus 1-2-3 issue - while Secunia, who Autonomy accuses of publishing misleading information, correctly reflects the fact that Autonomy offers patches.

However, this doesn't seem to be a concern for Autonomy or perhaps their legal department also treats their own customers in the same way as Secunia is treated?

What is misleading and confusing in this whole case is the apparent lack of co-ordination between Autonomy and Autonomy's OEM customers, the lack of clear, precise public statements about vulnerabilities and security fixes.

If Autonomy wants to avoid "misleading" and "confusing" communication, then Autonomy ought to start publishing bulletins such as those made by most other serious and established software vendors (e.g. Microsoft and their own customers IBM and Symantec) with clear information about the type of vulnerability, potential attack vectors, potential impacts, affected versions, and unaffected versions - it's really that simple.

Naturally, Autonomy should also communicate to their own customers (IBM and Symantec) that patches addressing vulnerabilities are available so that both their products and their Vulnerability Database services are updated.

Our response to these claims and accusations
Despite Autonomy's unsubstantiated legal threats, Secunia will quite legally continue to do vulnerability research in Autonomy products and any other products of interest. Naturally, Secunia will also continue to publish research articles and advisories in an unbiased, balanced, accurate, and truthful manner as we serve one purpose only: To provide accurate and reliable Vulnerability Intelligence to our customers and the Internet in general.

Secunia is in continuous, ongoing, and positive dialogues with most vendors including large professional organisations like Microsoft, IBM, Adobe, Symantec, Novell, Apple, and CA. All understand and respect the need for informing the public about vulnerabilities and prefer to co-ordinate and synchronise the publication with important Vulnerability Intelligence sources such as Secunia rather than battling to keep things secret. It is truly sad to see that certain vendors like Autonomy still behave like many software vendors did back in the previous millennium.


Copies of all correspondence in this "matter" is available below in chronological order, enjoy:
1. Email from Secunia 20071128.pdf
2. Letter from Autonomy 20071202.pdf
3. Email from Secunia 20071203.pdf
5. Letter from Autonomy 20071203.pdf
4. Email from Secunia 20071204.pdf
6. Letter from Autonomy 20071205.pdf


Kindest regards,

Thomas Kristensen
CTO, Secunia


Discuss this blog entry
A new thread in our forum is created. Activate the thread by commenting/discussing below.
Subject: Vendors still use the "legal" weapon
 
User Message
nikeshoxshoes RE: Vendors still use the "legal" weapon
Member 15th Sep, 2010 10:32
Score: 1
Posts: 1
User Since: 15th Sep 2010
System Score: N/A
Location: AR
Last edited on 15th Sep, 2010 10:33
good post
Was this reply relevant?
+1
-0
taffy078 RE: Vendors still use the "legal" weapon
Contributor 15th Sep, 2010 16:29
Score: 347
Posts: 1,019
User Since: 26th Feb 2009
System Score: 100%
Location: UK
(unknown source)
In these days, one would have believed that vendors have learned the lesson not to threaten with legal actions to withhold and suppress significant information about vulnerabilities in their products.


Are you able/willing to tell us which vendors do this?

--
taffy078, West Yorkshire, UK

Compaq Presario (OEM) 32 bit / AMD Athlon / 2 GB RAM
XP Home - SP3/ IE8/ Norton IS / Secunia PSI v2.0.0.4003
Was this reply relevant?
+2
-0
secunidoe RE: Vendors still use the "legal" weapon
Member 15th Sep, 2010 19:34
Score: 3
Posts: 3
User Since: 15th Sep 2010
System Score: N/A
Location: AX
Last edited on 15th Sep, 2010 19:35
(unknown source)
Are you able/willing to tell us which vendors do this?

Turns out this is an automated truncation of http://secunia.com/blog/15

(they put the link above the first post among tons of useless stuff; it would make a lot more sense to put it *inside* the first post, so that people can know the post has been truncated)

Edit: and it's actually a 3-year old post, but you wouldn't know that either just by looking at this thread
Was this reply relevant?
+3
-0
taffy078 RE: Vendors still use the "legal" weapon
Contributor 16th Sep, 2010 08:29
Score: 347
Posts: 1,019
User Since: 26th Feb 2009
System Score: 100%
Location: UK
thanks secunidoe.

That's an interesting exchange of correspondence - I was impressed by the Secunia CTO's clear & concise language. Especially how customers using OEM can be affected but unaware.

Perhaps Secunia will shed some light on why, as you point out, this has "come to light now, nearly three years later?

Also:
(1) did the litigation counsel for Autonomy see sense and not pursue?
(2) were the vulnerabilities resolved?

--
taffy078, West Yorkshire, UK

Compaq Presario (OEM) 32 bit / AMD Athlon / 2 GB RAM
XP Home - SP3/ IE8/ Norton IS / Secunia PSI v2.0.0.4003
Was this reply relevant?
+3
-0

deara2

RE: Vendors still use the "legal" weapon
[+]
This reply has been minimised due to a negative Relevancy Score.
Anthony Wells RE: Vendors still use the "legal" weapon
Expert Contributor 10th Nov, 2010 17:31
Score: 2050
Posts: 2,896
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

For taffy ,

The thread opened because the first poster to the actual blog comments section triggered it . The blog dates to December 2007 and the first post was by @nikeshoxshoes on 15 Setpember 2010 which is also the date of the Secunia opening cut down entry .

It is just the same as posting under an SA or Vulnerability report , as has been discussed at lenght elsewhere in the Forum .

Comments under a Blog open the thread in the "Open Discussion" sub-forum with the limitations described by @secunidoe .

Hope that clears up that point .

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+1
-0
taffy078 RE: Vendors still use the "legal" weapon
Contributor 10th Nov, 2010 22:07
Score: 347
Posts: 1,019
User Since: 26th Feb 2009
System Score: 100%
Location: UK
Thanks Anthony but
(1) did the litigation counsel for Autonomy see sense and not pursue?
(2) were the vulnerabilities resolved?




--
taffy078, West Yorkshire, UK

Compaq Presario (OEM) 32 bit / AMD Athlon / 2 GB RAM
XP Home - SP3/ IE8/ Norton IS / Secunia PSI v2.0.0.4003
Was this reply relevant?
+0
-0
Anthony Wells RE: Vendors still use the "legal" weapon
Expert Contributor 10th Nov, 2010 22:19
Score: 2050
Posts: 2,896
User Since: 19th Dec 2007
System Score: N/A
Location: N/A
Last edited on 10th Nov, 2010 22:20
Try asking Thomas Kristensen , taffy ; he's the one with the knowledge .

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0

-

You must be logged in to post a comment.



 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports & Papers
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2012 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability