5 ms·
I fear that because of the asymmetric power/financial balance between the parties involved, such a choice could easily lead to a kind of war, in which the compa
by elmo2you 6y ago
I fear that because of the asymmetric power/financial balance between the parties involved, such a choice could easily lead to a kind of war, in which the companies will have the upper hand. They will have may more means/resources at their disposal and when it gets ugly (out of the public eye) things could get nasty.
Please, don't get me wrong. On itself I think this whole responsible disclosure culture is bullshit. It wouldn't be if more companies actually treated it more sincerely. But I have seen too many companies abuse responsible disclosure, or simply hide behind bug hunting programs to limit/squash exposure (too many times even without fixing anything), and then burn anyone who doesn't want to play by rules they themselves set.
The problem is, there are far more things than just legal prosecution when this would turn into a clash between companies and security researchers. However, maybe a union or anonymous organization could level that playing field. Problem with that is that many security researchers also want recognition, at the same time as feeling safe (.. something about cake).
- TheButlerian 6y agoThey companies will still be under legal prosecution if they do something against the people that publish the leaks.
- gruez 6y agoJust publish it anonymously? Make a site called exploithub and host it as a hidden service. I'm sure most cybersecurity professionals wouldn't have problems accessing it.
- macintux 6y agoIf you’ve already disclosed it to the vendor, a leak of the information shortly thereafter would likely not be so anonymous.
- gruez 6y agoIf you're disclosing it to the vendor, then you're probably cooperating with them and are going to give them 90 days to fix it. If they don't fix it within that time, anonymously publish it a month or two after. That gives a total time of around 4-6 months between you discovering it and the "anonymous researcher" on exploithub "independently" discovering it.