Skip to content

Comment on Minecraft Migrated Account Session Vulnerability Security Advisoryparent

Comments

It's unlikely the case here but responsible disclosure is not always so simple and can make 0-day public disclosure a "reasonable response".

I have heard of cases where informing the company of a vulnerability and telling them "I will publicly disclose the vulnerability in N days" has resulted in security researchers being taken to court as a "blackmail attempt". Annoyingly I can't find the case I'm thinking of (though I've found numerous other unsettling ones such as [1]) but will update this comment if I do. One example of such madness is Dmitry Sklyarov[2] who was arrested under the DMCA's anti-circumvention laws for revealing that an e-book vendor used ROT13 to encrypt their documents.

A useful introduction to the complexity of public and responsible disclosure can be seen at the EFF's Vulnerability Reporting FAQ[3].

[1]: http://www.scmagazine.com.au/News/276780,security-researcher...

[2]: http://en.wikipedia.org/wiki/Dmitry_Sklyarov

[3]: https://www.eff.org/issues/coders/vulnerability-reporting-fa...

Yes, that approach is the wrong approach. "Responsible Disclosure" works both ways. The company with the software gets the vulnerability before the public, but they have to not try to sue/prosecute the security researcher. If companies are known to attack security researchers like you mention, then they can forget about responsible disclosure. Those companies will find out about vulnerabilities in the newspapers. Can't have your cake and eat it.

> It's unlikely the case here

Especially given the fact that Notch and Mojang have played Quake with Team Avo members.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.