19,411 views
The CCC supports the reporting of security vulnerabilities using the responsible disclosure or coordinated vulnerability disclosure procedure. Using the example of various vulnerabilities that we have reported in recent months, we show how disclosures can be carried out. Legal advice is not provided. In applied security research, hacker paragraphs continue to lead to great uncertainty. Those who report security vulnerabilities have to fear being reported and sued. The CCC therefore supports the reporting of security vulnerabilities. How does such a disclosure process actually work? In this presentation, we provide insights into practice and use current examples from the past few months to explain how we reported security vulnerabilities. We will also highlight typical challenges and possible conflicts. kantorkel, Linus Neumann https://events.ccc.de/congress/2024/h... #38c3 Licensed to the public under http://creativecommons.org/licenses/b...