Legal Pacts Are Silencing Vulnerability Researchers, Schneier Warns
Bruce Schneier highlights a talk by Kendra Albert at USENIX Security, arguing that modern bug bounty programs legally gag security researchers. These programs often force researchers into nondisclosure agreements that prevent them from publicly sharing vulnerability findings—even when companies don’t fix the bugs. According to Albert, this undermines the original spirit of coordinated vulnerability disclosure, as it restricts transparency and weakens researcher leverage
https://www.schneier.com/blog/archives/2025/11/legal-restrictions-on-vulnerability-disclosure.html
Comments
Post a Comment