vulnerability disclosure debate

CERT to disclose software flaws - Lemos paper

2000/10/09 : Lemos give his point of view on vulnerability disclosure debate.
"While Ranum is well-known in the industry for his black-and-white views on disclosure, most security professionals fall into a grey area."

ImageShack hacked in oddball security protest (anti-sec movement)

2009/07/13 : John Leyden explains how "Anti-Sec" broke into the big image hosting websites ImageShack.

Security in an Open Electronic Society - Levy reaction on Culp essay

White-Hat Hate Crimes on the Rise (Wired Paper)

2001 : "A group of black-hat hackers, in a campaign called "Project Mayhem," have declared war on white-hat hackers who've gone to work for security firms."
The 'Project Mayhem' is the battle declaration of full-disclosure against anti-sec.
Bug Bounty Programs Are Being Used to Buy Silence - Schneier Post

2020/04/03 : Bruce Schneier writes on the "Investigative report [by J.M. Porup] on how commercial bug-bounty programs like HackerOne, Bugcrowd, and SynAck are being used to silence researchers".

Schneier - Crypto-Gram February 15, 2003

2003/02/15 : Schneier published his monthly newsletter.
He talks this time on Locksmiths.

Information Anarchy: The Blame Game? - Edwards reaction on Culp essay

2001/10/23 : Edwards analyses Culp essay on information anarchy.

The realities of Disclosure : Morgenstern and Parker on Christey and Wysopal failure

2002/07/12 : Michael Morgenstern and Tom Parker point to the failure of Christey and Wysopal's willingness to put in place common measures for responsible disclosure.

Software Vulnerabilities: Full-, Responsible-, and Non-Disclosure - (Cencini, Yu and Chan publication)

2005/12/07 : Andrew Cencini, Kevin Yu, Tony Chan write upon the different choices of vulnerability disclosures.

