Site icon Secplicity – Security Simplified

Ethical Vulnerability Disclosure – Daily Security Byte

Ethical Vulnerability Disclosure

I believe in full but responsible vulnerability disclosure, and really appreciate researchers that spend the time and effort to find security flaws in products so the industry can fix them. The only caveat being, I also believe researchers should privately disclose these flaws first, and give the vendor sufficient time to fix them before releasing the full details. The intention isn’t to protect the vendor, rather to protect the customers that use the affected product. Today’s video covers an ethical dilemma over one research group’s disclosure of vulnerabilities in a medical device. Watch the video for the details, and let me know your thoughts on the matter.

Episode Runtime: 4:06

Direct YouTube Link: https://www.youtube.com/watch?v=l-AkwldvXOo

EPISODE REFERENCES:

— Corey Nachreiner, CISSP (@SecAdept)

Exit mobile version