Password manager maker Keeper sues Ars Technica and reporter Dan Goodin for story on a vulnerability in Keeper software, first highlighted by Google researcher
the company behind the product— is suing Dan and Ars. In the extraordinary complaint, Keeper says Dan ‘intended’ to cause harm http://www.documentcloud.org/ ... via @zackwhittaker http://twitter.com/... Matt Blaze / @mattblaze : In my professional opinion, suing those who discuss software vulnerabilities is itself a reliable indication of dangerously vulnerable software and incompetent security practices. For that reason, I will be avoiding Keeper Security products. https://twitter.com/... Kim Zetter / @kimzetter : This suit is ridiculous and will go away, but what a bad precedent this is for a security firm to set and what a dishonorable way to treat a journalist who has covered security for years and takes great pains to get things right @keepersecurity https://twitter.com/... Robert Graham's naughty list / @erratarob : Confirmed: Dan Goodin is not simply technical, but extraordinarily interested in getting the story right. This one time he interviewed me for a story, then told me I was wrong, and he was right. https://twitter.com/... Nicholas Weaver / @ncweaver : Let me get it straight, Keeper claims this is defamatory solely because the browser extension isn't mandatory, but a “separate program”? Who tolerates using a password manager without the corresponding browser extension?!? https://twitter.com/... Rafael Rivera / @withinrafael : Keeper story is interesting; the app isn't vulnerable, but the separately installed Browser Extension is. So technically, the vulnerable app wasn't preloaded, hence the defamation lawsuit. Tom Warren / @tomwarren : I wondered why this Keeper password manager junk ended up on my Windows PC. The maker is now suing a Ars Technica reporter for reporting on it. Bad look @keepersecurity http://www.zdnet.com/... Joseph Cox / @josephfcox : Keeper is looking for damages to be awarded, and have the article removed. Didn't even read the article last week, thanks for letting everyone know about it Keeper pic.twitter.com/y1virUSvm2 Matt Blaze / @mattblaze : As I've said repeatedly, how a vendor responds to reports of a vulnerability reveals far, far more about the security of a product than the vulnerability itself. Processes are much more significant than any particular bug. Keeper Security is failing badly in this respect. https://twitter.com/... See also Mediagazer
Context & Ripple Effects
Keeper Security is suing Ars Technica and reporter Dan Goodin over a story about a password-manager vulnerability that a Google researcher had first highlighted, with the complaint alleging Goodin 'intended' to cause harm. The suit lands in a disclosure ecosystem already strained: the earlier Atrient kiosk disclosure had devolved into competing claims of assault and blackmail between researchers and vendor.
The immediate reaction among security figures was sharply negative — Matt Blaze publicly said he would avoid Keeper products because suing those who discuss vulnerabilities signals bad security practice, and Kim Zetter called the suit a bad precedent. Two months later, reporting confirmed researchers and journalists were hesitating to publish vulnerability findings for fear of defamation action.
First-order effects
- Ars Technica and Dan Goodin now face a defamation-style complaint from a company whose product they covered, raising their legal exposure for routine security reporting.
- Keeper Security absorbs immediate reputational damage from its own community: Matt Blaze publicly boycotts its products and Kim Zetter condemns the precedent, turning a vulnerability story into a trust story.
Second-order effects
- Vendors gain a template for litigating unfavorable coverage — the same playbook visible in the Atrient dispute and later in Apple's suit against an ex-employee over Journal app leaks — pushing disputes out of technical channels and into courtrooms.
- Researchers and reporters recalibrate: follow-up reporting shows them hesitating to disclose or cover vulnerabilities at all, which slows the flow of findings that companies like Google's research teams rely on to get flaws fixed.
Third-order effects
- If legal retaliation becomes a standard vendor response, vulnerability disclosure shifts structurally toward private channels and away from public reporting, weakening the independent press function that surfaced this very flaw.
- The pattern also pressures platforms and publishers to weigh defamation risk against security journalism, an equilibrium tested again when Apple accused Project Zero of stoking fear over its attack reporting.
The trend: Security disclosure is migrating from a norms-based collaboration between researchers, press, and vendors into a legally contested arena where each side weaponizes lawsuits and counter-claims.