Responsible Disclosure
Noun · Security & Infosec · Origin: 2000
Definitions
The practice of privately notifying a vendor about a vulnerability and giving them reasonable time to patch it before publicly disclosing the details. A middle ground between full disclosure and keeping quiet.
In plain English: When a security researcher finds a bug, they tell the company first and give them time to fix it before telling the world.
Etymology
- c. 2000
- Security researcher Rain Forest Puppy proposes 'RFPolicy,' one of the first formal responsible disclosure guidelines
- 2001
- Scott Culp of Microsoft publishes 'It's Time to End Information Anarchy,' sparking fierce debate between full and responsible disclosure camps
- 2010s
- Bug bounty platforms (HackerOne, Bugcrowd) institutionalize responsible disclosure, paying researchers and standardizing timelines