1
00:00:00,000 --> 00:00:00,900
In this lesson,

2
00:00:00,900 --> 00:00:03,719
we're going to explore responsible disclosure programs.

3
00:00:03,719 --> 00:00:05,550
Responsible disclosure is a term used

4
00:00:05,550 --> 00:00:07,050
to describe the ethical practice

5
00:00:07,050 --> 00:00:09,450
where a security researcher is going to disclose information

6
00:00:09,450 --> 00:00:11,790
about a vulnerability in a software, hardware,

7
00:00:11,790 --> 00:00:13,920
or online service in a confidential manner

8
00:00:13,920 --> 00:00:15,300
to the relevant stakeholders,

9
00:00:15,300 --> 00:00:17,220
such as the software developers themself,

10
00:00:17,220 --> 00:00:19,710
or the company who created the product or service.

11
00:00:19,710 --> 00:00:21,270
With responsible disclosure,

12
00:00:21,270 --> 00:00:23,490
our goal is to allow the affected party enough time

13
00:00:23,490 --> 00:00:24,750
to address the vulnerability

14
00:00:24,750 --> 00:00:26,910
before a public disclosure occurs.

15
00:00:26,910 --> 00:00:29,340
So what does responsible disclosure look like?

16
00:00:29,340 --> 00:00:31,320
Well, let's pretend that a security researcher

17
00:00:31,320 --> 00:00:32,970
just discovered a new vulnerability

18
00:00:32,970 --> 00:00:34,950
in a particular software application.

19
00:00:34,950 --> 00:00:36,840
Before they post about it in their blog,

20
00:00:36,840 --> 00:00:38,760
they should first contact the owner or developer

21
00:00:38,760 --> 00:00:41,730
of that effective product, service, or system privately

22
00:00:41,730 --> 00:00:43,830
through some kind of official communication channel,

23
00:00:43,830 --> 00:00:45,060
like sending them an email

24
00:00:45,060 --> 00:00:47,460
to that organization's cybersecurity team.

25
00:00:47,460 --> 00:00:49,650
The researcher will usually provide the organization

26
00:00:49,650 --> 00:00:52,020
with enough information for them to fully understand

27
00:00:52,020 --> 00:00:53,910
and replicate that vulnerability.

28
00:00:53,910 --> 00:00:56,040
The security researcher and the organization

29
00:00:56,040 --> 00:00:57,390
will then agree upon a timeframe

30
00:00:57,390 --> 00:00:59,700
before a public disclosure is going to be made.

31
00:00:59,700 --> 00:01:01,290
That way, the organization can work

32
00:01:01,290 --> 00:01:04,110
to mitigate that vulnerability and deploy a security fix

33
00:01:04,110 --> 00:01:07,770
or hotfix to patch that software for all of its end users.

34
00:01:07,770 --> 00:01:09,600
Now, once the vulnerability has been addressed,

35
00:01:09,600 --> 00:01:12,480
or after the expiration of the agreed upon timeframe,

36
00:01:12,480 --> 00:01:13,980
the researcher will then be allowed

37
00:01:13,980 --> 00:01:15,600
to disclose the information publicly

38
00:01:15,600 --> 00:01:17,790
to the rest of the cybersecurity community.

39
00:01:17,790 --> 00:01:19,740
This process ensures that the vulnerability

40
00:01:19,740 --> 00:01:21,930
is not maliciously exploited by a threat actor,

41
00:01:21,930 --> 00:01:23,820
while legitimate end users are still waiting

42
00:01:23,820 --> 00:01:24,900
for the software developer

43
00:01:24,900 --> 00:01:27,060
to create some kind of a hotfix or security fix

44
00:01:27,060 --> 00:01:29,190
and then deploy it to all of their customers.

45
00:01:29,190 --> 00:01:31,140
This kind of responsible disclosure is great,

46
00:01:31,140 --> 00:01:33,810
but many organizations actually take it a step further

47
00:01:33,810 --> 00:01:36,420
by developing a robust responsible disclosure program

48
00:01:36,420 --> 00:01:38,460
known as a bug bounty program.

49
00:01:38,460 --> 00:01:40,620
Now, an organization can create a bug bounty program

50
00:01:40,620 --> 00:01:42,420
to encourage cybersecurity researchers

51
00:01:42,420 --> 00:01:43,980
to find and report vulnerabilities

52
00:01:43,980 --> 00:01:45,990
in the organization's own systems.

53
00:01:45,990 --> 00:01:47,400
By offering monetary rewards

54
00:01:47,400 --> 00:01:48,660
to the cybersecurity researchers

55
00:01:48,660 --> 00:01:50,220
when they find a validated vulnerability

56
00:01:50,220 --> 00:01:53,040
in the organization's software, the security researchers

57
00:01:53,040 --> 00:01:54,720
are being incentivized to participate

58
00:01:54,720 --> 00:01:57,180
in our organization's responsible disclosure program

59
00:01:57,180 --> 00:01:59,370
in a more controlled and ethical manner.

60
00:01:59,370 --> 00:02:00,750
Now, bug bounty programs

61
00:02:00,750 --> 00:02:02,790
can be run internally by an organization,

62
00:02:02,790 --> 00:02:04,050
or they can be facilitated

63
00:02:04,050 --> 00:02:06,360
through a third-party platform that specializes

64
00:02:06,360 --> 00:02:09,300
in connecting security researchers with an organization.

65
00:02:09,300 --> 00:02:10,530
There are many publicly available

66
00:02:10,530 --> 00:02:12,210
bug bounty competitions available

67
00:02:12,210 --> 00:02:15,330
on platforms like HackerOne, Bugcrowd, and Synack,

68
00:02:15,330 --> 00:02:17,070
which all provide security researchers

69
00:02:17,070 --> 00:02:18,090
a structured environment

70
00:02:18,090 --> 00:02:19,500
where they can submit the vulnerabilities

71
00:02:19,500 --> 00:02:21,660
that they discovered directly for verification,

72
00:02:21,660 --> 00:02:23,490
prioritization, and mitigation

73
00:02:23,490 --> 00:02:25,860
by the owners of the software or service.

74
00:02:25,860 --> 00:02:27,420
Now, your organization will find

75
00:02:27,420 --> 00:02:29,010
that there are several benefits to implementing

76
00:02:29,010 --> 00:02:31,980
one of these responsible disclosure and bug bounty programs.

77
00:02:31,980 --> 00:02:34,770
First, bug bounty programs help to increase the security

78
00:02:34,770 --> 00:02:35,940
of your organization.

79
00:02:35,940 --> 00:02:37,110
By opening up the systems

80
00:02:37,110 --> 00:02:39,750
to additional scrutiny by external security researchers,

81
00:02:39,750 --> 00:02:42,270
an organization can uncover and fix vulnerabilities

82
00:02:42,270 --> 00:02:44,520
that might have been overlooked by their internal teams

83
00:02:44,520 --> 00:02:46,860
or external consultants and penetration testers

84
00:02:46,860 --> 00:02:49,530
that may have been contracted to do it for them.

85
00:02:49,530 --> 00:02:51,120
Second, bug bounty programs

86
00:02:51,120 --> 00:02:52,980
can foster community collaboration.

87
00:02:52,980 --> 00:02:54,570
By establishing a channel of communication

88
00:02:54,570 --> 00:02:55,920
with security researchers,

89
00:02:55,920 --> 00:02:57,660
organizations can build a community

90
00:02:57,660 --> 00:02:58,950
that's invested in the security

91
00:02:58,950 --> 00:03:01,080
and reliability of their products.

92
00:03:01,080 --> 00:03:04,200
Third, bug bounty programs are very cost-effective.

93
00:03:04,200 --> 00:03:06,630
Traditional security assessments and penetration testing

94
00:03:06,630 --> 00:03:08,400
can be really expensive to perform,

95
00:03:08,400 --> 00:03:10,620
but a bug bounty program allows the organization

96
00:03:10,620 --> 00:03:11,970
to only pay for vulnerabilities

97
00:03:11,970 --> 00:03:13,500
that were found in their software,

98
00:03:13,500 --> 00:03:16,140
and the compensation level can be based on the severity

99
00:03:16,140 --> 00:03:18,000
or seriousness of the vulnerability

100
00:03:18,000 --> 00:03:20,880
that's being submitted by that cybersecurity researcher.

101
00:03:20,880 --> 00:03:23,580
But we also have some challenges and considerations

102
00:03:23,580 --> 00:03:25,380
that come with running a responsible disclosure

103
00:03:25,380 --> 00:03:27,120
or bug bounty program.

104
00:03:27,120 --> 00:03:29,550
Your organization has to ensure clear communication

105
00:03:29,550 --> 00:03:31,770
is occurring regarding the scope of the program,

106
00:03:31,770 --> 00:03:32,700
the rules of engagement,

107
00:03:32,700 --> 00:03:34,440
and the rewards that are going to be issued

108
00:03:34,440 --> 00:03:36,510
to ensure your program will be successful.

109
00:03:36,510 --> 00:03:38,820
It's also critical to establish legal protections

110
00:03:38,820 --> 00:03:40,440
for your cybersecurity researchers

111
00:03:40,440 --> 00:03:41,760
who are going to be acting in good faith

112
00:03:41,760 --> 00:03:44,010
to ensure they're not held liable for any issues

113
00:03:44,010 --> 00:03:46,470
that may occur as a result of their participation

114
00:03:46,470 --> 00:03:48,090
inside of the bug bounty program

115
00:03:48,090 --> 00:03:50,010
as long as they stay within the rules of engagement

116
00:03:50,010 --> 00:03:52,500
that you've set up for your particular program.

117
00:03:52,500 --> 00:03:55,290
So, if you want to create an effective responsible disclosure

118
00:03:55,290 --> 00:03:56,580
or bug bounty program,

119
00:03:56,580 --> 00:03:57,960
you need to make sure you're also following

120
00:03:57,960 --> 00:04:01,500
some good industry best practices for doing these programs.

121
00:04:01,500 --> 00:04:03,960
Your program must have a clearly defined scope

122
00:04:03,960 --> 00:04:06,750
so people know what is and is not part of your program

123
00:04:06,750 --> 00:04:08,580
in terms of what they're allowed to do.

124
00:04:08,580 --> 00:04:11,610
Also, you want to clearly tell your researchers what testing

125
00:04:11,610 --> 00:04:14,310
or programing is going to be allowed and on what systems.

126
00:04:14,310 --> 00:04:15,450
That way, they can make sure

127
00:04:15,450 --> 00:04:16,800
they're not affecting your operations

128
00:04:16,800 --> 00:04:17,910
while they're still trying to find

129
00:04:17,910 --> 00:04:19,829
all these security vulnerabilities.

130
00:04:19,829 --> 00:04:21,450
Your organization should also establish

131
00:04:21,450 --> 00:04:22,950
a proper communication channel

132
00:04:22,950 --> 00:04:24,630
to ensure there's a clear responsive channel

133
00:04:24,630 --> 00:04:26,130
for reporting any vulnerabilities

134
00:04:26,130 --> 00:04:28,350
that a cybersecurity researcher finds.

135
00:04:28,350 --> 00:04:30,120
Additionally, your program needs to set up

136
00:04:30,120 --> 00:04:31,680
some sort of a reward structure

137
00:04:31,680 --> 00:04:34,320
that will clearly define the available rewards or bounties

138
00:04:34,320 --> 00:04:36,330
for any newly discovered vulnerabilities,

139
00:04:36,330 --> 00:04:38,970
and the levels of these bounties are going to be in alignment

140
00:04:38,970 --> 00:04:40,590
with the risk and potential impact

141
00:04:40,590 --> 00:04:42,360
of the discovered vulnerability.

142
00:04:42,360 --> 00:04:44,730
If somebody finds a remote code execution

143
00:04:44,730 --> 00:04:46,260
that we would consider to be a level 9

144
00:04:46,260 --> 00:04:47,880
or level 10 vulnerability,

145
00:04:47,880 --> 00:04:49,350
that's going to pay a lot more money

146
00:04:49,350 --> 00:04:50,850
than something like an information leak

147
00:04:50,850 --> 00:04:53,970
that may only be a level 1 or level 2 vulnerability.

148
00:04:53,970 --> 00:04:55,620
Another key to a successful program

149
00:04:55,620 --> 00:04:57,690
is to create clear timeframes for the acknowledgement,

150
00:04:57,690 --> 00:05:01,140
validation, and remediation of any reported vulnerabilities.

151
00:05:01,140 --> 00:05:03,420
After all, if a security researcher takes the time

152
00:05:03,420 --> 00:05:05,700
to find a vulnerability in your system and reports it,

153
00:05:05,700 --> 00:05:07,290
they want to make sure they're hearing from you

154
00:05:07,290 --> 00:05:09,330
that you've received it, that you've analyzed it,

155
00:05:09,330 --> 00:05:11,700
and that they've been awarded some sort of compensation

156
00:05:11,700 --> 00:05:13,680
or bounty for finding that vulnerability

157
00:05:13,680 --> 00:05:16,950
once you verify it was a real vulnerability in your system.

158
00:05:16,950 --> 00:05:19,380
Also, you want to make sure you're having full transparency

159
00:05:19,380 --> 00:05:21,270
inside of your bug bounty program.

160
00:05:21,270 --> 00:05:23,460
That way, once the vulnerabilities are resolved,

161
00:05:23,460 --> 00:05:24,600
you can also share what you learn

162
00:05:24,600 --> 00:05:26,670
with others in your community or your industry

163
00:05:26,670 --> 00:05:29,700
so that all of our systems can become more secure over time.

164
00:05:29,700 --> 00:05:32,880
So remember, when we talk about a responsible disclosure,

165
00:05:32,880 --> 00:05:33,840
we're talking about a term

166
00:05:33,840 --> 00:05:35,670
that's used to describe an ethical practice

167
00:05:35,670 --> 00:05:38,010
where a security researcher is going to disclose information

168
00:05:38,010 --> 00:05:40,470
about vulnerabilities in a piece of software, hardware,

169
00:05:40,470 --> 00:05:42,900
or online service in a confidential manner

170
00:05:42,900 --> 00:05:44,550
to the relevant stakeholders.

171
00:05:44,550 --> 00:05:46,860
Responsible disclosure and bug bounty programs

172
00:05:46,860 --> 00:05:48,150
are going to represent a collaborative

173
00:05:48,150 --> 00:05:50,040
and proactive approach to cybersecurity

174
00:05:50,040 --> 00:05:51,930
by engaging with the wider security community

175
00:05:51,930 --> 00:05:54,780
to create a more secure and robust digital landscape.

176
00:05:54,780 --> 00:05:57,960
These programs can turn potential adversaries into allies

177
00:05:57,960 --> 00:05:59,550
by leveraging the collective intelligence

178
00:05:59,550 --> 00:06:01,680
and skills of the global cybersecurity community

179
00:06:01,680 --> 00:06:02,760
to find vulnerabilities

180
00:06:02,760 --> 00:06:05,160
in our organization's products and services too.

