Summary

Portrait of Cory Doctorow Cory Doctorow Indefensible: The W3C Says Companies Should Get to Decide When and How Security Researchers Reveal… (2017)

The World Wide Web Consortium has just signaled its intention to deliberately create legal jeopardy for security researchers who reveal defects in its members' products, unless the security researchers get the approval of its members prior to revealing the embarrassing mistakes those members have made in creating their products. It's a move that will put literally billions of people at risk as researchers are chilled from investigating and publishing on browsers that follow W3C standards.
Source: Wikisource

Portrait of Cory Doctorow Cory Doctorow Indefensible: The W3C Says Companies Should Get to Decide When and How Security Researchers Reveal… (2017)

We at EFF call on the W3C to reconvene its earlier negotiations to defang the legal consequences of its DRM work, and in so doing to transform its security disclosure work from a weapon to a normative guideline. It's one thing to help companies figure out how to make an attractive offer to the researchers who investigate browser security, but it's another thing altogether to standardize browser technology that empowers companies to sue the researchers who decline to take them up on the offer.
Source: Wikisource

Portrait of Cory Doctorow Cory Doctorow Indefensible: The W3C Says Companies Should Get to Decide When and How Security Researchers Reveal… (2017)

Under almost every circumstance in almost every country, true facts about defects in products are always lawful to disclose. No one -- especially not the companies involved -- gets to dictate to security researchers, product reviewers and users when and how they can discuss mistakes that manufacturers have made.
Source: Wikisource

Get perspective with Kwize: daily news enlightened by great literature