|
|
|
|
|
by EricMausler
1013 days ago
|
|
I proposed protected legal channels for researchers. It does remove any pressure from companies. Their neck is still on the line. It adds pressure to companies because it creates a paper trail. It enables good faith companies to work with researchers as well. They can even have researchers contact each other if they are both looking into the same thing. There's a lot of good that can come of it Companies can already rush out any product they want with no security. Lack of security is still a risk, regardless of how we address researching vulnerabilities |
|
If the production company declines, that DOES remove pressure from that company.
Companies that rush out rubbish products can presently be named and shamed by independent, uncooperative or even adversarial researchers. Your proposal considers that research illegitimate unless said dodgy company decides to open itself up to scrutiny, which it obviously would not be inclined to do.
If you want to suggest the market would respond by not selecting products from such an opaque company, look into how many WhatsApp users care about auditable, open source code vs. those using Signal.