/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How a vulnerability disclosure by researchers to Atrient, a vendor of player reward kiosks for casinos, led to competing claims of assault and blackmail

“Ethical hackers” tried to disclose problems to a casino software company—it got messy.  —  People who find security vulnerabilities commonly run … Tweets: @vickerysec , @vickerysec , and @k8em0 Tweets: Chris Vickery / @vickerysec : There is a very simple rule of thumb that should be followed if you legitimately poke around on the internet as legitimate security research. Here it is Part 1: Do not ever ever ever ever even suggest the idea of accepting money from a company that did not proactively engage you. Chris Vickery / @vickerysec : Part 2: Do not ever ever ever ever even consider signing a non-disclosure agreement surrounding the notification (even if they are pressuring you hard to do so). This isn't hard. If you suggest or accept money, *_they_will_100%_accuse_you_of_ extortion_*. http://arstechnica.com/... Katie Moussouris / @k8em0 : Vulnerability disclosure is an art. Comments by me & @todb about that disclosure debacle, by @thepacketrat . Which disclosure debacle? Whichever one you want. This one's about Atrient, but it could be about so many others - minus the assault allegations. Ok that one's unique. http://twitter.com/...

Ars Technica Sean Gallagher

Context & Ripple Effects

This is the second act of an already ugly story: a February report covered how Atrient allegedly ignored serious security flaws in its casino player-reward kiosks and how one researcher was assaulted by the company's COO. Ars now adds the fuller picture — the disclosure devolved into competing claims of assault and blackmail between vendor and researchers, with Chris Vickery (@vickerysec) and Katie Moussouris (@thepacketrat) named in the fray.

The arc is familiar. The corpus shows disclosure disputes repeatedly tipping into open conflict rather than resolution: Facebook's fight with a researcher over Instagram bug compensation, Keeper suing Ars Technica over a vulnerability story, and FireEye taking a security firm to court over disclosure in 2015. Atrient is that pattern at its most extreme — past litigation into criminal allegations.

First-order effects

  • Casinos running Atrient kiosks are the immediate losers: while the company battles researchers publicly, the underlying kiosk flaws it allegedly ignored remain the live exposure.
  • Vickery and Moussouris face direct personal and professional risk — blackmail accusations against security researchers are reputationally corrosive even when contested, which is why Vickery is publicly laying out rules for unsolicited disclosures.

Second-order effects

  • Vendors watching this will see unsolicited reports as a legal hazard, not free QA — pushing them to formalize paid, pre-agreed channels where terms like compensation can't later be reframed as extortion.
  • Researchers, in turn, have incentive to route findings through established bug-bounty intermediaries — the model Moussouris helped pioneer — rather than approaching unengaged vendors directly.

Third-order effects

  • If disclosure breakdowns keep ending in lawsuits and criminal claims, the industry structurally splits into formalized programs with legal cover and an informal gray zone where researchers touching unengaged vendors carry real personal liability.
  • For regulated verticals like gambling hardware, the deeper problem is what happens to unpatched flaws when both sides retreat into legal warfare — the kiosk operators and their customers inherit the risk neither party resolves.

The trend: Vulnerability disclosure is migrating from informal researcher-vendor contact toward legally structured bounty programs, as each high-profile collapse like Atrient's raises the cost of doing it any other way.