Discussion about this post

User's avatar
Adrian Sanabria's avatar

"To start, here’s how the current vulnerability disclosure process works"

Whose vulnerability disclosure process are we talking about? Since I can remember, there have always been several options available to the researcher/discoverer: full disclosure, try to sell the vuln, notify the vendor, or do nothing. Submitting to a CNA is the only option that seems new to me, based on my experiences.

It's a lot of work and pain to go through coordinated disclosure and deal with CVEs, so most of the vulns that I've discovered over the years don't have one. I did get a CVE reserved in one case, but the vendor took years to fix it, and by the time they did, I no longer had access to the email I used to reserve the CVE and never closed the loop.

The clearest incentive to disclose a vulnerability a certain way, IMO, has been the bug bounty platforms and the incentive of getting paid, or at least recognition, with some assurance that you wouldn't get arrested for your trouble.

I've never been aware of a commonly agreed upon way of disclosing vulnerabilities. This is historically one of the most hotly debated cybersecurity topics.

No posts

Ready for more?