Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • About Bonfire
SuffolkLITLab
@SuffolkLITLab@esq.social  ·  activity timestamp 2 days ago

TL;DR: Kendra Albert's talk at USENIX Security highlights how legal agreements on vulnerability disclosure hinder researchers and allow companies to neglect fixing security flaws, undermining the goals of the responsible disclosure movement. https://www.schneier.com/blog/archives/2025/11/legal-restrictions-on-vulnerability-disclosure.html #law #tech #legaltech ⚖️ 🤖 #autosum

Schneier on Security

Legal Restrictions on Vulnerability Disclosure - Schneier on Security

Kendra Albert gave an excellent talk at USENIX Security this year, pointing out that the legal agreements surrounding vulnerability disclosure muzzle researchers while allowing companies to not fix the vulnerabilities—exactly the opposite of what the responsible disclosure movement of the early 2000s was supposed to prevent. This is the talk. Thirty years ago, a debate raged over whether vulnerability disclosure was good for computer security. On one side, full disclosure advocates argued that software bugs weren’t getting fixed and wouldn’t get fixed if companies that made insecure software wasn’t called out publicly. On the other side, companies argued that full disclosure led to exploitation of unpatched vulnerabilities, especially if they were hard to fix. After blog posts, public debates, and countless mailing list flame wars, there emerged a compromise solution: coordinated vulnerability disclosure, where vulnerabilities were disclosed after a period of confidentiality where vendors can attempt to fix things. Although full disclosure fell out of fashion, disclosure won and security through obscurity lost. We’ve lived happily ever after since...
  • Copy link
  • Flag this post
  • Block
Log in

bonfire of thepocolips

come over, warm up. coffee?

bonfire of thepocolips: About · Code of conduct · Privacy ·
bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Code of Conduct
Home
Login