Vulnerability Disclosure Considered Stressful


연구 분야: Strategies



학회: ACM SIGCOMM Computer Communication Review, Volume 53, Issue 2


초록

Vulnerability disclosure is a widely recognized practice in the software industry, but there is a lack of literature detailing the firsthand experiences of researchers who have gone through the process. This work aims to bridge that gap by sharing our personal experience of accidentally discovering a DNS vulnerability and navigating the vulnerability disclosure process for the first time. We document our mistakes and highlight the important lessons we learned, such as the fact that public disclosure can be effective but can also be more time-consuming and emotionally taxing than anticipated. Additionally, we discuss the ethical considerations and potential consequences that may arise during each step of the disclosure process. Lastly, drawing from our own experiences, we identify and discuss issues with the current disclosure process and propose recommendations for its improvement. Our ultimate aim is to provide valuable insights to fellow researchers who may encounter similar challenges in the future and contribute to the enhancement of the overall disclosure process for the benefit of the wider community.


Author Profile
Giovane C M Moura

SIDN Labs and TU Delft Arnhem and Delft The Netherlands

Andorra
Author Profile
John S. Heidemann

USC/ISI and CS Dept. Los Angeles California USA

Andorra

📄 논문 정보

발행 연도 2023년
인용수 6
출판 국가 Andorra
사이트 ACM
좋아요 수 0

연관 논문 목록 (128건)