Tutorials/Tips

A “Grey Hat” Guide for Security Researchers

The following is a verbatim reproduction of Jennifer Granick’s original post
In counseling computer security researchers, I have found the law to be a real obstacle to solving vulnerabilities. The muddy nature of the laws that regulate computers and code, coupled with a series of abusive lawsuits, gives researchers real reason to worry that they might be sued if they publish their research or go straight to the affected vendor.

By reporting the security flaw, the researcher reveals that she may have committed unlawful activity, which might invite a lawsuit or criminal investigation. On the other hand, withholding information means a potentially serious security flaw may go unremedied. I discuss this problem, and offer some ideas about what researchers can do about it, in a new document called “A ‘Grey Hat’ Guide”. Constructive feedback is welcome, as I can use it to improve the paper.


You may read the Grey Hat Guide here

Related Posts

Customizing Simply Linux 5 Simply Linux 5 is a distro from the same team that publishes ALT Linux. The first review of this distro on this site has just been published. This pos...
Sabayon 5.3 installation guide One of the best features introduced in Sabayon 5.3, the latest upgrade to the Gentoo-based, multi-purpose Linux distribution is the installer. The old...
6 things to do after installing OpenMandriva Lx 2013.0 OpenMandriva Lx 2013.0 is the first stable release of OpenMandriva, a Linux desktop distribution that is a community-continuation of what used to be M...
Managing startup applications on Deepin 2014 Since Deepin 2014 was released, I've been trying to figure how how to add and remove applications from the startup applications manager. Turns out tha...
How to install Oracle JRE on Fedora 20 and use alternatives to switch between it and OpenJ... All the Java components installed on Fedora (20) are provided by OpenJDK (Open Java Development Kit), a Free Software implementation of Java SE (Stand...
MATE vs Cinnamon Read an updated version of this article at Your choice: Cinnamon or MATE. MATE and Cinnamon are two recent additions to the list of desktop environ...

We Recommend These Vendors and Free Offers

Launch an SSD VPS in Europe, USA, Asia & Australia on Vultr's KVM-based Cloud platform starting at $5:00/month (15 GB SSD, 768 MB of RAM).

Deploy an SSD Cloud server in 55 seconds on DigitalOcean. Built for developers and starting at $5:00/month (20 GB SSD, 512 MB of RAM).

Want to become an expert ethical hacker and penetration tester? Request your free video training course of Online Penetration Testing and Ethical Hacking

Whether you're new to Linux or are a Linux guru, you can learn a lot more about the Linux kernel by requesting your free ebook of Linux Kernel In A Nutshell.


Leave a Comment

Your email address will not be published. Required fields are marked *

*