{"id":4353,"date":"2017-10-31T09:46:55","date_gmt":"2017-10-31T06:46:55","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=4353"},"modified":"2019-11-15T14:47:12","modified_gmt":"2019-11-15T11:47:12","slug":"even-more-transparency","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/even-more-transparency\/4353\/","title":{"rendered":"Astrologlar 2018&#8217;i \u015feffafl\u0131k y\u0131l\u0131 ilan etti. Bug Bounty (\u00d6d\u00fcl Avc\u0131l\u0131\u011f\u0131) program\u0131m\u0131zdaki \u00f6d\u00fcller yirmi kat artt\u0131r\u0131ld\u0131."},"content":{"rendered":"<p>Herkese merhaba,<\/p>\n<p>Muhte\u015fem haberlerim var.<\/p>\n<p>Hatta \u015f\u00f6yle s\u00f6yleyeyim,<\/p>\n<p>MUHTE\u015eEM HABERLER\u0130M VAR!<\/p>\n<p>Global \u015eeffafl\u0131k Giri\u015fimi\u2019mizi ba\u015flatmak \u00fczereyiz. Ad\u0131ndan belli oldu\u011fu \u00fczere bu giri\u015fim tamamen \u015feffafl\u0131kla ilgili. \u015eimdi konunun ayr\u0131nt\u0131lar\u0131n\u0131 inceleyelim.<br>\nBu arada yaz\u0131n\u0131n devam\u0131nda siber g\u00fcvenlik uzmanlar\u0131n\u0131 sevindirecek bir teklifimiz olacak. Yani yaz\u0131y\u0131 sonuna kadar okuman\u0131z\u0131 tavsiye ederim!<\/p>\n<p><em>Global \u015eeffafl\u0131k Giri\u015fim tam olarak nedir?<\/em><\/p>\n<p>Yak\u0131n gelecekte, daha do\u011frusu gelecek senenin ba\u015flar\u0131nda \u00fcr\u00fcnlerimizin kaynak kodlar\u0131n\u0131 \u00fc\u00e7\u00fcnc\u00fc taraf analizine ve denetimine a\u00e7aca\u011f\u0131z. Uzun s\u00fcredir bu t\u00fcr i\u00e7 denetimler ger\u00e7ekle\u015ftiriyoruz. Ancak bunun art\u0131k yeterli olmad\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcnd\u00fc\u011f\u00fcm\u00fcz i\u00e7in bir ad\u0131m daha atmaya karar verdik. Saklayacak hi\u00e7bir \u015feyimiz yok.<\/p>\n<p>A\u00e7\u0131lmas\u0131 planlanan \u00fc\u00e7 \u015eeffafl\u0131k Merkezi\u2019nden birisi 2018 y\u0131l\u0131n\u0131n ba\u015flar\u0131nda a\u00e7\u0131lacak. 2020 y\u0131l\u0131na kadar bu \u00fc\u00e7 merkez Avrupa, Asya ve ABD\u2019de \u00e7al\u0131\u015fmalar\u0131na ba\u015flayacak.<\/p>\n<p>Sadece \u00fcr\u00fcnlerimizin kaynak kodlar\u0131n\u0131 de\u011fil ayn\u0131 zamanda AV veritabanlar\u0131m\u0131zdaki g\u00fcncellemeleri ve yaz\u0131l\u0131m g\u00fcncellemelerimizi de denetime a\u00e7aca\u011f\u0131z. Yani HERHANG\u0130 B\u0130R YERDE haberimizin olmad\u0131\u011f\u0131 bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 veya arka kap\u0131 varsa bunlar ortaya \u00e7\u0131kacak ve \u00fczerini \u00f6rtme ihtimalimiz olmayacakt\u0131r.<\/p>\n<p>Zaten b\u00f6yle bir niyetimiz de yok.<\/p>\n<p><em>Bunu neden yap\u0131yoruz?<\/em><\/p>\n<p>\u00c7ok basit. Siber g\u00fcvenlik g\u00fcven \u00fczerine kuruludur ve \u015feffafl\u0131k olmadan g\u00fcven de olmaz. Hayati \u00f6nem ta\u015f\u0131yan her konuda oldu\u011fu gibi siber g\u00fcvenlikte de b\u00f6yle bir \u015fey asla m\u00fcmk\u00fcn de\u011fildir.<\/p>\n<p>Mesela b\u0131\u00e7a\u011f\u0131 elinde tutan doktora g\u00fcvenmezseniz ameliyat olmazs\u0131n\u0131z. \u0130\u00e7eriyi g\u00f6rmenize izin verilmeyen bir anaokuluna \u00e7ocu\u011funuzu emanet etmezsiniz. Marketlerden \u00fczerinde son kullanma tarihi olmayan bir \u00fcr\u00fcn\u00fc sat\u0131n almazs\u0131n\u0131z. Tabii ki burada ger\u00e7ek hatalardan de\u011fil yaln\u0131zca hata olas\u0131l\u0131\u011f\u0131ndan bahsetti\u011fimizi vurgulamak isterim. S\u00f6z konusu olan hayati \u00f6nem ta\u015f\u0131yan bir konuysa bundan asla taviz verilmemelidir.<\/p>\n<p>Bu d\u00fc\u015f\u00fcnceye bizden daha \u00e7ok inanan hi\u00e7 kimse yoktur.<\/p>\n<p>Kullan\u0131c\u0131lar\u0131m\u0131z, hem bizim i\u00e7in hem de u\u00e7 noktalar i\u00e7in b\u00fcy\u00fck \u00f6nem ta\u015f\u0131r. Bu nedenle dijital anlamda \u00f6rt\u00fclerimizden tamamen s\u0131yr\u0131laca\u011f\u0131z. \u00dcr\u00fcnlerimizin bir t\u00fcr r\u00f6ntgenini \u00e7ekerek BT d\u00fcnyas\u0131n\u0131n ba\u015f\u0131ndaki sihirli haleyi de yok edece\u011fiz. Asl\u0131na bakarsan\u0131z bizim durumumuzda ortada bir sihir oldu\u011fundan bahsetmek do\u011fru de\u011fil. Yaln\u0131zca temiz kodlar kullan\u0131yoruz ve hile yapm\u0131yoruz.<\/p>\n<p>\u00c7alkant\u0131l\u0131 zamanlarda ya\u015fad\u0131\u011f\u0131m\u0131z\u0131 ve devrim niteli\u011finde de\u011fi\u015fimlere tan\u0131kl\u0131k etti\u011fimizi muhtemelen fark etmi\u015fsinizdir. Art\u0131k duygular\u0131n ger\u00e7eklerden daha \u00f6nemli hale geldi\u011fi ger\u00e7ek \u00f6tesi (post-truth) \u00e7a\u011f\u0131nday\u0131z. B\u00f6yle bir d\u00fcnyada g\u00fcvenilir ve g\u00fcvenli bir limana denk geldi\u011fimizde hemen demir atmal\u0131 ve k\u0131y\u0131ya yana\u015fmal\u0131y\u0131z.<\/p>\n<p>Kaspersky Lab olarak biz de bu limanlardan biriyiz ve bunu kan\u0131tlamaya haz\u0131r\u0131z.<\/p>\n<p>Ba\u015far\u0131m\u0131z\u0131n yirmi y\u0131ll\u0131k modern geli\u015fimimizin bir sonucu oldu\u011funa ger\u00e7ekten inan\u0131yorum. Bu giri\u015fimi \u015fimdi ba\u015flatmam\u0131\u015f olsayd\u0131k bir ka\u00e7 y\u0131l i\u00e7inde yine ba\u015flatacakt\u0131k. Ya da biz yapmasayd\u0131k ba\u015fkalar\u0131 yapacakt\u0131. Bu nedenle Amerikal\u0131 siyaset\u00e7ilere de \u00e7ok te\u015fekk\u00fcr etmek istiyorum. Onlar sayesinde yine global ortalaman\u0131n \u00f6n\u00fcne ge\u00e7tik. Birka\u00e7 y\u0131l i\u00e7inde bu t\u00fcr bir \u015feffafl\u0131\u011f\u0131n sekt\u00f6r i\u00e7in yeni bir standart haline gelece\u011finden eminim. \u00d6nc\u00fc olmak her zaman iyidir.<br>\n\u00d6nemli not: Kaynak kodlar\u0131m\u0131z\u0131 herkese a\u00e7aca\u011f\u0131m\u0131z\u0131 d\u00fc\u015f\u00fcnerek endi\u015felenmemelisiniz. Temel amac\u0131m\u0131z m\u00fc\u015fterilerimizi korumakt\u0131r. Bu nedenle kaynak kodlar\u0131m\u0131z\u0131n yaln\u0131zca d\u00fczenleyiciler ve yetkili emniyet te\u015fkilatlar\u0131yla payla\u015f\u0131lmas\u0131n\u0131 sa\u011flayaca\u011f\u0131z. Bu payla\u015f\u0131m, Hassas S\u0131n\u0131fland\u0131r\u0131lm\u0131\u015f Bilgi Tesisi\u2019nde (<a href=\"https:\/\/en.wikipedia.org\/wiki\/Sensitive_Compartmented_Information_Facility\" target=\"_blank\" rel=\"noopener nofollow\">SCIF<\/a>) bizim g\u00f6zetimimiz alt\u0131nda ger\u00e7ekle\u015ftirilecektir. Bilgiler hi\u00e7bir d\u0131\u015f kurulu\u015f ile fiziksel olarak PAYLA\u015eILMAYACAKTIR. \u0130nceleme, d\u00fczenleyicileri davet etti\u011fimiz ba\u011f\u0131ms\u0131z bir merkezde ger\u00e7ekle\u015ftirilecektir.<\/p>\n<p>Kaynak kodlar\u0131m\u0131z\u0131n herhangi birine flash bellekle verilmeyece\u011fini bir kez daha hat\u0131rlatmak isterim. Bu s\u00fcre\u00e7 son derece s\u0131k\u0131 bir \u015fekilde takip edilmesine ra\u011fmen \u015feffafl\u0131k prosed\u00fcr\u00fc \u00fc\u00e7\u00fcnc\u00fc taraf\u0131n sa\u011flad\u0131\u011f\u0131 bir SCIF ile ger\u00e7ekle\u015ftirilecektir.<\/p>\n<p>\u015eimdi s\u0131ra yaz\u0131n\u0131n ba\u015f\u0131nda bahsetti\u011fim teklife geldi.<\/p>\n<p>Global \u015eeffafl\u0131k Giri\u015fimi \u00e7er\u00e7evesinde bug bounty (\u00f6d\u00fcl avc\u0131l\u0131\u011f\u0131) program\u0131m\u0131z\u0131 iyile\u015ftirdik. Bu teklifle ilgili t\u00fcm cazip ayr\u0131nt\u0131lar bu y\u0131l sonuna kadar a\u00e7\u0131klanm\u0131\u015f olacak. Ancak k\u00fc\u00e7\u00fck bir ipucu vermek gerekirse, en b\u00fcy\u00fck \u00f6d\u00fcl\u00fcn 100.000 USD\u2019ye \u00e7\u0131kar\u0131laca\u011f\u0131n\u0131 s\u00f6yleyebiliriz. Bu rakam daha \u00f6nceki en y\u00fcksek teklifin 20 kat\u0131.<\/p>\n<p>Yani, d\u00fcnyan\u0131n b\u00fct\u00fcn siber g\u00fcvenlik uzmanlar\u0131, <a href=\"mailto:transparency@kaspersky.com\" target=\"_blank\" rel=\"noopener\">birle\u015fin<\/a>! Birlikte g\u00fcvensizli\u011fi ortadan kald\u0131ral\u0131m ve d\u00fcnyan\u0131n her yerinden insanlar\u0131 korumaya devam edelim.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Global \u015eeffafl\u0131k Giri\u015fimi&#8217;mizi ba\u015flatmak \u00fczereyiz. Ad\u0131ndan belli oldu\u011fu \u00fczere bu giri\u015fim tamamen \u015feffafl\u0131kla ilgili. \u015eimdi konunun ayr\u0131nt\u0131lar\u0131n\u0131 inceleyelim.<br \/>\nBu arada yaz\u0131n\u0131n devam\u0131nda siber g\u00fcvenlik uzmanlar\u0131n\u0131 sevindirecek bir teklifimiz olacak. Yani yaz\u0131y\u0131 sonuna kadar okuman\u0131z\u0131 tavsiye ederim!<\/p>\n","protected":false},"author":13,"featured_media":4354,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1352],"tags":[1405,744,352,1421,1395,1420,1407,551],"class_list":{"0":"post-4353","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-special-projects","9":"tag-bug-bounty","10":"tag-guvenlik","11":"tag-kaspersky-lab","12":"tag-kod-analizi","13":"tag-odul","14":"tag-odul-avciligi","15":"tag-seffaflik","16":"tag-urunler-2"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/even-more-transparency\/4353\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/even-more-transparency\/9764\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/even-more-transparency\/13126\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/even-more-transparency\/12032\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/even-more-transparency\/11648\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/even-more-transparency\/14694\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/even-more-transparency\/14416\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/even-more-transparency\/19105\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/even-more-transparency\/19943\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/even-more-transparency\/9725\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/even-more-transparency\/8453\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/even-more-transparency\/15131\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/even-more-transparency\/18573\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/even-more-transparency\/19000\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/even-more-transparency\/18992\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/kaspersky-lab\/","name":"Kaspersky Lab"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=4353"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4353\/revisions"}],"predecessor-version":[{"id":7013,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4353\/revisions\/7013"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/4354"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=4353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=4353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=4353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}