Responsible Disclosure

Noun · Security & Infosec · Origin: 2000

Definitions

  1. The practice of privately notifying a vendor about a vulnerability and giving them reasonable time to patch it before publicly disclosing the details. A middle ground between full disclosure and keeping quiet.

    In plain English: When a security researcher finds a bug, they tell the company first and give them time to fix it before telling the world.

Etymology

c. 2000
Security researcher Rain Forest Puppy proposes 'RFPolicy,' one of the first formal responsible disclosure guidelines
2001
Scott Culp of Microsoft publishes 'It's Time to End Information Anarchy,' sparking fierce debate between full and responsible disclosure camps
2010s
Bug bounty platforms (HackerOne, Bugcrowd) institutionalize responsible disclosure, paying researchers and standardizing timelines

Related Terms