{"id":11233,"date":"2022-02-01T07:00:00","date_gmt":"2022-02-01T15:00:00","guid":{"rendered":"https:\/\/formtek.com\/blog\/?p=11233"},"modified":"2021-07-24T15:56:41","modified_gmt":"2021-07-24T23:56:41","slug":"security-pros-and-cons-of-white-hat-discovered-vulnerabilities","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/security-pros-and-cons-of-white-hat-discovered-vulnerabilities\/","title":{"rendered":"Security: Pros and Cons of White-Hat-Discovered Vulnerabilities"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">White-hat ethical hackers work to find vulnerabilities in popular apps and software and attempt to alert the authors of the problem to avoid future exploits from the Black-Hat hacker bad guys.  Good in theory.  But does this approach just tip the scales towards the black-hats, giving them free surveillance that they can attempt to use and exploit before users are able to roll out security patches that would fix the discovered problems?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/en.wikipedia.org\/wiki\/Adam_Segal\" data-type=\"URL\" data-id=\"https:\/\/en.wikipedia.org\/wiki\/Adam_Segal\">Adam Segal<\/a>, author of &#8220;The Hacked World Order&#8221;, <a href=\"https:\/\/www.csoonline.com\/article\/3186225\/black-hat-hackers-more-daring-and-experienced-than-white-hat-hackers.html\" data-type=\"URL\" data-id=\"https:\/\/www.csoonline.com\/article\/3186225\/black-hat-hackers-more-daring-and-experienced-than-white-hat-hackers.html\">told CSO that<\/a> \u201cblack-hats are ahead of white-hats. That is symptomatic of the larger problem in cybersecurity that offense still has the edge over defense. The defender has to worry about millions of lines of code, thousands of devices, thousands of networks. The attacker only has to be right once.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One easy way for hackers to crack systems is to exploit unpatched known problems. There are a lot of problems out there. <a href=\"https:\/\/www.bugcrowd.com\/press-release\/bugcrowd-study-reveals-65-increase-in-discovery-of-high-risk-vulnerabilities-in-2020-amid-covid-19-pandemic\/\">BugCrowd<\/a> in 2020 reported a 65 percent increase in priority-one vulnerability  submissions, the most severe type of bug that could cause critical damage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Public vulnerabilities are a tip-off to black-hat attackers of problems.  Once attackers know of a problem they can work to develop an exploit.  Paradoxically, a vendor&#8217;s patch to fix a problem is often a gift to the attacker.  Patches provide hackers with the solution that fixes the problem.  How? Patches can be reverse engineered and the patch code often clearly points out the exact cause of the flaw, making it easier for the attacker to come up with code that can exploit the problem, and that exploit code can then be used to target systems that are yet to be patched.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.morphisec.com\/hubfs\/2020%20State%20of%20Endpoint%20Security%20Final.pdf\" data-type=\"URL\" data-id=\"https:\/\/www.morphisec.com\/hubfs\/2020%20State%20of%20Endpoint%20Security%20Final.pdf\">One study<\/a> found that it takes on average 97 days for an organization to test and deploy a patch.  Many organizations want to make sure that the new software doesn&#8217;t introduce additional unintended problems.  The delay in patching provides a window of opportunity to hackers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-133a\" data-type=\"URL\" data-id=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/aa20-133a\">A US government report found<\/a> that &#8220;foreign cyber actors continue to exploit publicly known\u2014and often dated\u2014software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available.&#8221;<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-pros-and-cons-of-white-hat-discovered-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>White-hat ethical hackers work to find vulnerabilities in popular apps and software and attempt to alert the authors of the problem to avoid future exploits from the Black-Hat hacker bad guys. Good in theory. But does this approach just tip<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/security-pros-and-cons-of-white-hat-discovered-vulnerabilities\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-11233","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=11233"}],"version-history":[{"count":1,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11233\/revisions"}],"predecessor-version":[{"id":11234,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/11233\/revisions\/11234"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=11233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=11233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=11233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}