A “Grey Hat” Guide for Security Researchers

The following is a verbatim reproduction of Jennifer Granick’s original post
In counseling computer security researchers, I have found the law to be a real obstacle to solving vulnerabilities. The muddy nature of the laws that regulate computers and code, coupled with a series of abusive lawsuits, gives researchers real reason to worry that they might be sued if they publish their research or go straight to the affected vendor.

By reporting the security flaw, the researcher reveals that she may have committed unlawful activity, which might invite a lawsuit or criminal investigation. On the other hand, withholding information means a potentially serious security flaw may go unremedied. I discuss this problem, and offer some ideas about what researchers can do about it, in a new document called “A ‘Grey Hat’ Guide”. Constructive feedback is welcome, as I can use it to improve the paper.


You may read the Grey Hat Guide here

Related Posts

Is your browser safe against tracking? Use Panopticlick to find out Worried about privacy, about the websites you visit tracking you, whether you accept their cookies or not? Panopticlick to the rescue! Panopticl...
Dual-boot Windows 8 or Windows 7 and Ubuntu 13.10, with Ubuntu on a btrfs filesystem This tutorial offers a step-by-step guide on how to dual-boot Windows 8 and Ubuntu 13.10 on a single hard disk drive (HDD), with Ubuntu on a btrfs fil...
Linux Mint 10 manual disk partitioning guide Linux Mint 10, aka Julia, is the latest stable release of Linux Mint, a desktop-oriented distribution based on Ubuntu. Just like earlier releases of L...
A Guide to DRM-Free Living Welcome to our brief guide to living a DRM-free existence. We want to provide a range of links pointing you toward online stores, video/music players,...
Guest session and guest user accounts in Ubuntu If you are reading this article on a Ubuntu-powered computer, odds are that it is your computer. Whether it is a notebook, netbook, or a standard desk...
Pardus 2009.2 review Pardus is a desktop-oriented Linux distribution sponsored and developed by the Scientific & Technological Research Council of Turkey. It's not a perfe...

We Recommend These Vendors

Launch an SSD VPS in Europe, USA, Asia & Australia on Vultr's KVM-based Cloud platform starting at $5:00/month (15 GB SSD, 768 MB of RAM).

Deploy an SSD Cloud server in 55 seconds on DigitalOcean. Built for developers and starting at $5:00/month (20 GB SSD, 512 MB of RAM).


Leave a Comment

Your email address will not be published. Required fields are marked *

*