01 / 01

Why security researchers deserve better than one-way forms

Vulnerability Reports Are Not Special Anymore

Source: Filippo Valsorda

Hacker News • 247 points

02

The Broken Model

What's wrong with vulnerability disclosure today

The Traditional Disclosure Process

  • 01
    Find vulnerability Researcher discovers security issue in vendor's product
  • 02
    Fill out form Drop info into one-way submission system
  • 03
    Wait indefinitely No feedback, no timeline, no accountability
  • 04
    Hope for the best Maybe get credited, maybe never hear back
247
Hacker News points on this discussion
Indicating widespread frustration in the security community
05

Why Reports Got Demoted

The shift from VIP treatment to ticket queue

Then vs. Now: How Reports Are Treated

Early Days Respected
  • Personal email to engineers
  • Fast response & collaboration
  • Researcher treated as partner
  • Mutual respect
Today Problem
  • Anonymous web forms
  • Black hole submissions
  • Ticket in a queue
  • Silent vendors
Vulnerability reports are not special anymore.
They're just tickets in a queue.
Filippo Valsorda

Rethink Vulnerability Handling

Transparency, accountability, and respect should be the baseline

words.filippo.io/vuln-reports/
Made with AirSlide
𝕏 in