Microsoft has been urged to reconsider its position on removing exploits from GitHub, the code repository which it acquired in 2018, after an incident in which it removed an exploit for Microsoft Exchange Server from the site.
The security firm Tenable said in a statement on Tuesday that when an exploit was removed, the security community was unable to analyse its implications, mitigations, and detections.
“Meanwhile, attackers were busy infiltrating Microsoft Exchange servers across the globe en masse,” the infosec firm said. “It would be foolish to think that removing the PoC from GitHub meant that no one would have access to it. It’s quite the opposite, actually.
“It meant that defenders — providers of essential services, critical industries and the everyday security engineer — would lose the access they needed to understand the PoC even as attackers moved to underground forums to share it widely.”
In the last week of April, Microsoft called for “feedback on our policy around security research, malware, and exploits on the platform so that the security community can collaborate on GitHub under a clearer set of terms. We want to be more clear about our expectations for keeping GitHub, and the various package registries that call GitHub home, a safe community”.
The PoC code for the Exchange Server vulnerability, known as ProxyLogon, was posted back on GitHub by someone other than the original author after it was removed.
“GitHub is an important platform for collaborating and sharing vulnerability intelligence,” Tenable wrote. “It is one of the most popular platforms in the security community for a reason.
“With that kind of power comes responsibility to continue to share information openly, transparently and quickly. However, when implicit trust in a platform is shaken, it takes a lot more than post-facto justification of previous actions for it to be regained and maintained.
“There is a path forward by ensuring that material which can be used for defensive purposes is not lumped in the same bucket as weaponised malware. GitHub’s responsibility here is to ensure that the defenders stay ahead in the game and not cause information asymmetry by making it more difficult for security professionals to access this type of sensitive information.”
There have been other instances of censorship by Microsoft after it became the owner of GitHub. In November last year, the source code for the youtube-dl script, which can be used to download YouTube videos from the command-line, was taken down by GitHub after a complaint from the Recording Industry Association of America, a group of which Microsoft is a member.
In June last year, a researcher released exploit code for taking advantage of a vulnerability in Microsoft’s implementation of the server message block protocol in Windows, a flaw that was described as SMBGhost at the time it became known.
Researchers have anticipated that there would be a clash of interests with the new owner. Soon after the purchase of GitHub, 97 open-source developers threatened to move their projects away unless Microsoft ended its contract with the US Immigration and Customs Enforcement.
In 2019, there were protests over this contract at the annual GitHub conference, with a number of employees resigning.
Tenable said: “Security through obscurity will never work. GitHub could and should be used by the security community to co-ordinate defence more easily.
“The revisions in the latest iteration of the policy are a good start. However, there are still multiple caveats that could put the security community at a disadvantage, especially when there is an instance of widespread exploitation. We recommend Microsoft remove any verbiage around actions that would censor dual use content on GitHub in any form.”
GRAND OPENING OF THE ITWIRE SHOP
The much awaited iTWire Shop is now open to our readers.
Visit the iTWire Shop, a leading destination for stylish accessories, gear & gadgets, lifestyle products and everyday portable office essentials, drones, zoom lenses for smartphones, software and online training.
PLUS Big Brands include: Apple, Lenovo, LG, Samsung, Sennheiser and many more.
Products available for any country.
We hope you enjoy and find value in the much anticipated iTWire Shop.
INTRODUCING ITWIRE TV
iTWire TV offers a unique value to the Tech Sector by providing a range of video interviews, news, views and reviews, and also provides the opportunity for vendors to promote your company and your marketing messages.
We work with you to develop the message and conduct the interview or product review in a safe and collaborative way. Unlike other Tech YouTube channels, we create a story around your message and post that on the homepage of ITWire, linking to your message.
In addition, your interview post message can be displayed in up to 7 different post displays on our the iTWire.com site to drive traffic and readers to your video content and downloads. This can be a significant Lead Generation opportunity for your business.
We also provide 3 videos in one recording/sitting if you require so that you have a series of videos to promote to your customers. Your sales team can add your emails to sales collateral and to the footer of their sales and marketing emails.
See the latest in Tech News, Views, Interviews, Reviews, Product Promos and Events. Plus funny videos from our readers and customers.