Through the Looking Glass: How Open Source Projects See Vulnerability Disclosure

No ratings

Presented at BlackHat Europe 2023 by

A security researcher submits their vulnerability report to an open source project (when they can find a confidential way to do so!). That launches several events in the affected project. In this talk, Marta will explain the reasons behind typical reactions. The main part will focus on common myths, misunderstandings, and communication errors that arise in these situations. The goal is to foster a better understanding between security researchers and project teams.Drawing from her experience in enhancing reporting processes of projects hosted by the Eclipse Foundation, Marta will share four typical reactions from developers, providing illustrative examples. She will explain the underlying reasons behind those responses and offer hints on addressing them. Then she will touch on the frequent cases of low-quality security reports, using artificial examples to demonstrate situations that can badly influence the reputation of the entire security research community.The talk will conclude by outlining the various improvements implemented by the Eclipse Foundation to facilitate reporting and response mechanisms for both researchers and developers based on observations from the first part.