Preparing the Village - Lessons Learned in Cross-Industry Vulnerability Disclosure

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

On Monday, October 16, 2017, the world awoke to news of a protocol vulnerability in WPA/WPA2. Branded as the "KRACK Attack", this vulnerability impacted virtually every device with a wireless router. As soon as the vulnerability was announced, many vendors announced fixes. This was the result of a large scale coordinated disclosure effort organized by the Industry Consortium for Advancement of Security on the Internet (ICASI). Through collaboration among members, partners, and the researchers, this coordinated disclosure minimized the impact of this vulnerability.During this session, the President of ICASI will provide insight into how this coordination took place and explore what this experience means moving forward. This will be an open and honest conversation about what happened and will touch on topics such as what worked well, what did not, who was notified and how those notifications took place, and what lessons learned this experience has for FIRST’s work in Multi-Party Vulnerability Disclosure.The call action for participants will focus on tips on when to coordinate, practical skills for multi-party coordination, better coordination, and how to enable quick understandings for defender audiences.