It's always a scary experience.
The funny thing is according to them I was the only contributor from 2016 to the end of 2017. So they must not get many reports.
Since then they did develop a disclosure program, but it would be great to hear from anyone else that reported things to them after the end of 2017.
Probably because there's no obvious way to submit one.
Huh.
Whatever issue will immediately become a political football, and will end up being not only ineffective at the initial intention, but also include terrible side effects and dangerous footguns. Whether this is the result of a basically broken system of legislature, or of allowing the laws be drafted by the people they are supposed to protect against, or a combination of both, or something else entirely, I'm not qualified to say.
But I can say this: when I hear of some political ambition to make something better with a new law, I don't expect it to go well.
Better to remove barriers and things that silo and centralize power.
To counteract this a consumer group or union of those affected would be required, but that's a bit tough when they are usually the ones spending the money, not earning it.
If someone discovers a security vulnerability in a computer system, and they notify the operator or party responsible for maintenance of the system, then, starting 90 days after the notification was received, they may publicly disclose the vulnerability without fear of civil or legal repercussions.
If they use the vulnerability to exploit a system that is outside of their own administrative control (beyond developing a proof of concept), or transfer the information with intent to facilitate third party exploitation of the vulnerability, then the above protections do not apply.
I’m sure a lawyer worth their salt could turn that into an iron-clad law.
It wasn't the public disclosure Chase retaliated over here. The disclosure came after the retaliation.
Best we can hope for is that the EU or some other trigger-happy regulators do the same for security as they tried to do for privacy: mandate a dedicated security contact that legally has to respond to your disclosure. Then at least we'll have some form of direct contact and not have to resort to twitter for "secure" disclosure.