News: 1715257811

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

VMware security advisories now behind bureaucratic Broadcom barricade

(2024/05/09)


Much to the chagrin of security pros, VMware security advisories are now only viewable if users sign up for a Broadcom Support account first.

Granted, it's free to register a support account, but the change, which was announced earlier this week, may create added friction for infosec professionals looking for details on the bugs they need to squish.

VMware announced the change on Tuesday via a blog post that didn't specify the reason for what will be perceived to be a step backward in openness and transparency. We asked Broadcom, its new owner, for further details but it didn't immediately reply.

[1]

URLs for older VMware security advisories will still work, so there's no need to change any browser bookmarks, they'll just instead redirect to the Broadcom Support Portal.

[2]

[3]

End-user computing (EUC) products are the only exception here. Security advisories for these will still appear in the old feed and won't be made available inside Broadcom's Support Portal.

Even better news: there are plans in place to allow Broadcom Support accounts to receive automatic notifications about new or modified advisories, but that feature isn't working yet.

[4]

"Based on customer entitlements and customer settings, the Support Portal will send out notifications to customers that have signed up to receive notifications for new or modified security advisories," [5]blogged Monty Ijzerman, staff technical program manager at VMware's product security incident response team.

"However, at this time, Support Portal is not yet prepared to send out these notifications when a VMware Security Advisory is published or modified."

Infosec experts widely criticized the move. The main concerns are weakened transparency around security, and some feel it may make the job of aggregating exposure to vulnerabilities a more difficult task.

X post from upset infosec expert

Speaking to The Register , application security expert Sean Wright said: "This is yet another move in a list of recent changes that Broadcom has made which may cause some controversy. While I understand their desire to move the VMWare brand under their own brand, their approach is questionable.

"While it appears that individual vulnerabilities are publicly available on the Broadcom Support Portal, it will make it harder for security teams to keep track of all vulnerabilities across their VMWare product estate. Many will be unwilling to create yet another account for this purpose.

[6]

"Also worth asking is how mechanisms such as RSS feeds would work, or if at all. Many teams will rely on such mechanisms to have some form of automation for new advisories. Ultimately for some, this may turn out to be yet another reason to look to other alternative products."

Some have gone so far as to [7]call on national security agencies in the EU and US to halt Broadcom's latest move, saying "this is not acceptable."

[8]VMware waves goodbye to AWS middleman as Broadcom takes the reins

[9]AWS promotes itself as alternative to its own VMware service

[10]VMware by Broadcom blinks again – this time easing change for cloud service providers

[11]VMware's end-user compute community told to brace for 'Omnissa' shift

CISA's official stance on information sharing is that it is "essential to furthering cybersecurity for the nation." It says information should be shared rapidly and seamlessly, and it appears Broadcom's efforts to account-wall its security information may go against this widely accepted industry ideal.

Beyond the negativity directed toward the changes around security advisory accessibility, VMware customers and channel partners have voiced myriad concerns about Broadcom's acquisition.

Fears of what could become of VMware were rife long before the 2023 acquisition by Broadcom, which was perceived by Symantec customers as a company that worsens the entities it absorbs.

Sysadmins [12]told us back in 2022 that following Broadcom's takeover of [13]Symantec , product evolution had slowed and prices were driven up. Industry sources suspected that these were to discourage unwelcome customers.

Similar fears surrounded the situation at VMware. Broadcom soon did away with VMware's perpetual licenses, favoring a subscription model. For context, VMware was planning to switch to subscriptions before Broadcom entered the equation, and a [14]lifeline was thrown to customers already on these licenses.

That didn't stop European cloud trade body CISPE from [15]criticizing Broadcom for the move. Its gripe wasn't with subscriptions, but the company's framing of the changes as pro-innovation and pro-competition.

CISPE said Broadcom was ignoring the concerns about packaging products together, meaning customers could be paying for products they don't want. It also raised concerns about price hikes, which El Reg sources have previously said to be in the [16]500 to 600 percent region . Some customers' license costs have risen from $8 million to $100 million, we're told.

The trade body also said Broadcom's changes were anti-cloud, requiring cloud services providers to license a minimum of 3,500 cores and a minimum three-year contract.

Separate security issues were also raised, specifically that the patch support for VMware perpetual license holders was "insulting in its limitations," CISPE said. Only patches for critical vulnerabilities would be offered unless customers moved to a subscription. CISPE said this "verges on racketeering."

Broadcom insists it's committed to providing value for customers and partners, and that it has taken customer feedback into account with its offerings. ®

Get our [17]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjzzIfRDlZcGfHvZCost0AAAAAI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjzzIfRDlZcGfHvZCost0AAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjzzIfRDlZcGfHvZCost0AAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjzzIfRDlZcGfHvZCost0AAAAAI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://blogs.vmware.com/security/2024/05/where-did-my-vmware-security-advisories-go.html

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjzzIfRDlZcGfHvZCost0AAAAAI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://cyberplace.social/@GossiTheDog/112405316987162977

[8] https://www.theregister.com/2024/05/07/broadcom_vmware_aws/

[9] https://www.theregister.com/2024/05/03/vmc_on_aws_changes/

[10] https://www.theregister.com/2024/05/01/vmware_cloud_partner_changes/

[11] https://www.theregister.com/2024/04/26/omnissa_vmware_euc_changes_coming/

[12] https://www.theregister.com/2022/05/31/vmware_broadcom_acquisition_customer_reaction/

[13] https://www.theregister.com/2019/08/09/broadcom_buys_symantec_for_10bn/

[14] https://www.theregister.com/2024/04/16/broadcom_vmware_perpetual_license_support/

[15] https://www.theregister.com/2024/04/24/cispe_broadcom_vmware/

[16] https://www.theregister.com/2024/04/05/the_world_is_watching_broadcom/

[17] https://whitepapers.theregister.com/



A new milestone

b0llchit

The enshittification of security.

What could possibly go wrong?

Wondering why

Mike 137

Given the extent of easily automatable web activity snooping telemetry gathering, I've never understood mandatory free of charge registration to access web sites. It adds hardly anything of value to what can be acquired, particularly if those accessing a site do so from a corporate client.

Re: Wondering why

Anonymous Coward

It makes it easier to spam you with adverts

Re: Wondering why

StewartWhite

Given Broadcom's recent "form" in massively increasing their "customer" (aka mark) fees my bet is that after a few months this will become a paid-for only service with an increase in price over the years massively exceeding inflation (witness Google and their recent price gouging for reCAPTCHA). Broadcom will then whinge when there's the inevitable customer security breach that it's because the customer in question hasn't upgraded their systems.

Microsoft's previous pathetic sliding scale reduction in security log duration depending on the version of MS365 purchased whilst bleating on about "Customer security being our highest priority" is yet another example of where this obviously translates to "$$$$$ is our highest priority".

Anonymous Coward

They want to use the data to see who's still using VMware as that's what 99.9% of users will be doing. If you were previously a cloud partner of any description and paying monthly, your contract enabled VMware to conduct a physical audit, not just whilst the contract was in force but up to two years after it was terminated. I'm not a lawyer, so not sure if it's still possible for Broadcom/VMware to audit you given it was them who terminated the contract, but it won't stop them trying. I suspect they might be turning int the next Oracle regarding audits, if you're aware of how Orible operate.

gryphon

Broadcom are also very hectoring about not using out of date software versions even if properly licensed.

Mountain meet mole hill

Anonymous Coward

So the whole crux of this article is a free support login is needed to read the advisories. That is a huge edge case, I've never seen that before. Wow, imagine the concept of having to sign up first before getting access. That's crazy, just what is the Internet coming to??!?

That is so irresponsible of Broadcom. They actually want to know who is reading their security advisories. VMWare was so much better - any random threat actor had anonymous access to read the advisories. Just insane that Broadcom would want to restrict security information to known individuals such as their customers.

Thank goodness I am able to post this comment without having to sign up on The Register....errr...nevermind.

(For those without humor, this post contains sarcasm)

VMWare end user product licensing

Anonymous Coward

As a long time user of VMware Fusion on my Mac desktop, I'm shocked to suddenly be told that I must now "migrate" my VMware support account over to Broadcom. Shocked, because as I try to do this I discover that the migration process requires a "site id" that I don't have, because I'm an end user, not a corporate customer.

So now I'm unable to access any of my product license details.

Nice one, Broadcom. NOT.

I am more bored than you could ever possibly be. Go back to work.