4 ms·
They stopped communicating with Rapid7. When you stop, you know, coordinating with the researchers they are free to do what they want. Rapid7 likely gave them t
by bitexploder 3y ago
They stopped communicating with Rapid7. When you stop, you know, coordinating with the researchers they are free to do what they want. Rapid7 likely gave them their entire process, set expectations and coordinated with JetBrains up front. This is sort of an “ethical standard” most firms and security researchers follow. The timeline’s they use and the exact process they follow varies. The key goal is to keep the vulnerabilities public and properly credit the researchers. Coordinated disclosure is an olive branch, so you know exactly what to expect and how to behave. It is generally very reasonable. If you break the terms or spirit of this process the researchers have no reason or real recourse but to release their info whenever they want and feel is appropriate. Don’t break the faith, the researchers are essentially doing you a favor by following this policy. It really is not hard to communicate and act in good faith on both sides. I have coordinated the release of dozens of vulnerabilities. I have definitely disclosed them after companies ghosted us or threatened us hoping to make the issue go away.
JetBrains got cute and cut the researchers out of the loop. Now future researchers will likely treat JetBrains as a bad faith actor and proceed accordingly.
- _cenw 3y agoI've done responsible disclosure myself. But I wouldn't dunk on a vendor for not telling me they released a fix on the same day because I'd probably just assume it's internal communication issues. And then attribute their late publishing of associated CVEs to my threats. It all feels a bit petty and rushed (to get the credit?) to me. Especially if a fix it cut into a regular release and not a hotfix, it likely just made it in by accident.
- bitexploder 3y agoI would reserve judgment until seeing everything. I am just advocating from the general perspective of a security firm. I ran one for a decade and disclosed a lot of vulns. My experience was almost always that vendors were the ones creating issues. We tried our best due to how sensitive issues can be and viewed each vendor or company as a potential customer. Rapid7 could have easily been rude or unreasonable, but that is not the norm for sure. It probably was a little petty, but we don’t know what the lead up was either. You just get tired of being jerked around as a security firm when you do this a lot.