/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Security researchers and reporters hesitate to report vulnerabilities fearing defamation lawsuits and other legal action

Zack Whittaker / ZDNet :

ZDNet Zack Whittaker

Discussion

  • @neil_neilzone Neil Brown on x
    This is a superb piece, and definitely food for thought for lawyers who represent tech companies, and for those companies themselves: is suing a security researcher *really* the best way forward? http://twitter.com/...
  • @emilymaxima @emilymaxima on x
    Great article on tech vs. legality. I'd specifically like to thank Zack for talking to so many female security researchers for this article http://twitter.com/...
  • @sarahjamielewis Sarah Jamie Lewis on x
    I spoke to @zackwhittaker about how legal threats have affected the shape and direction of my research. This is not an area my life I talk about much, I kept most of the details off the record but this is an important issue to understand, so please read. http://twitter.com/...
  • @j0hnnyxm4s Johnny Xmas on x
    Zack is giving a voice to those of us who are being silenced by talking about this massive elephant in the #infosec room. It was great to be able to tell him my story. http://twitter.com/...
  • @threatresearch Andrew Brandt on x
    Just like SLAPP lawsuits, these are designed to punish people expressing security concerns, more than anything. I'd like to see the anti-SLAPP laws that exist amended to cover this type of abusive, punitive practice. http://twitter.com/...
  • @daniel_bilar Daniel Bilar on x
    Highlighted quote is from @J0hnnyXm4s : In his youth, uncovered a flaw in magnetic stripe found in his university's student ID cards. Got expelled from school and the unnamed company was “livid at the loss of a huge client” & sued him for slander ("claims were verifiably true"). …
  • @ihackedwhat Render Man on x
    Ive not been sued or charged, yet. I'm sitting on two widespread critical infrastructure vulns because of the shoot-first mentality. The scale of it is such that there's no way to get hold of everyone to ensure things are fixed. No gov help in doing the right thing. http://twitte…
  • @cesarcer Cesar Cerrudo on x
    Sadly this happens, having reported hundred of vulns and dealt with dozens of angry vendors I can say that problems can be avoided, just need to be careful asking for lawyer advise and have a plan b if something goes wrong http://twitter.com/...