Security researchers could face lawsuits or even prosecution. Bugcrowd founder: “Hackers and even lay people that identify security risks – they function as the internet’s immune system” More organizations are adopting researcher-friendly vulnerability disclosure programs or bug bounty programs. In this video interview, Casey Ellis and Edward Farrell discuss how the legal environment around security research is evolving. They say legal protections are needed for responsible security researchers to be able to report vulnerabilities to organizations with no disclosure policies. The two experts also discuss why legal protections need for responsible researchers.”]
Source: https://www.govinfosecurity.com/reporting-security-bugs-be-fraught-tension-a-17765