White hats versus vendors: the fight goes on

Tim Ring · Computer Fraud & Security · 2015

Education Pro is a highly sensitive piece of software considering it is used only in schools. That’s because the package, from Impero Solutions, is deployed by around a quarter of Britain’s secondary schools to record and restrict their pupils’ Internet use – including their access to extremist Jihadi and neo-Nazi websites. So when in June security researcher Zammis Clark posted a proof-of-concept on GitHub showing how hackers could potentially seize the Pro data schools had on their students – without telling Impero first – he stirred up a storm. Far from thanking him, the vendor called in its lawyers, who gave Clark four days to remove his exploit and all references to it, or they would start legal action. He complied. From lone researchers to elite teams such as Google's Project Zero, bug hunters have one thing in common – they regularly clash with the vendors whose flaws they are revealing. Their running battles arouse strong emotions across the security community and sometimes lead to legal action. But why, after years of clashes, debates and rival manifestos, are we seemingly no nearer to finding the ‘right’ approach to bug disclosure? Tim Ring reports.

Read the paper · More papers on PaperTik