> Markdown version of [/videos/232-we-deserve-rights](https://www.wearedevelopers.com/videos/232-we-deserve-rights). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # We Deserve Rights Security researchers are routinely punished for making software safer. One in four ethical hackers now refuses to report critical bugs. It is time to demand legal rights. - **Speakers:** Chloé Messdaghi - **Event:** World Congress 2021 - **Published:** June 28, 2021 - **Duration:** 41:32 - **URL:** https://www.wearedevelopers.com/videos/232-we-deserve-rights ## Summary The hacker community is facing a critical legal and PR crisis, where well-intentioned security researchers are routinely punished for making software safer. A major driver of this issue is the conflation of "hackers" (who operate with permission and protective intent) and malicious "attackers." Outdated legislation like the Computer Fraud and Abuse Act (CFAA), originally passed in the 1980s, has been repeatedly weaponized by large tech companies to silence researchers reporting legitimate vulnerabilities under the threat of prosecution. Because 94% of the Forbes Global 2000 lack formalized Vulnerability Disclosure Policies (VDPs), ethical bug hunters are often forced to contact uninformed marketing or legal teams, transforming standard system disclosures into hostile PR battles. The tragic case of Aaron Swartz exemplifies the devastating human cost of vague anti-hacking laws and redundancies in prosecution. These systemic barriers lead directly to a self-defeating scenario: one in four hackers refuses to report critical bugs out of fear, ultimately leaving systems far more exposed to actual malicious actors. To secure legal rights and safe harbors for security professionals, the industry must fundamentally change its social constructs and media portrayals. Developers and advocates are encouraged to consistently correct journalists who misuse the term "hacker," push organizations to adopt clear, plain-language VDPs through platforms like Bugcrowd or HackerOne, and leverage open blueprints from disclose.io. Normalizing ethical hacking requires stepping away from stereotypical imagery—such as avoiding the "hoodie" trope on camera—and engaging directly with elected representatives to reform cybersecurity legislation. **Keywords:** vulnerability disclosure policy, bug bounty programs, security researcher legal rights, computer fraud and abuse act, CFAA compliance, safe harbor legislation, ethical bug hunting, malicious attacker distinction, tech media representation, disclose.io, corporate security compliance, hacker rights advocacy, infosec community, social construct biases ## Chapters 1. **Grassroots advocacy for security researcher rights** (00:03) — Exploring the movements working to protect hackers and change public perception. 1. **Understanding the difference between hackers and attackers** (03:12) — How intent separates ethical security researchers from malicious threat actors. 1. **The legal risks of reporting corporate vulnerabilities** (04:28) — A real-world case study of a security researcher facing a lawsuit for reporting a bug. 1. **Challenging socially constructed fears around the hacker community** (08:29) — How subconscious biases and social norms shape negative legal and public perceptions. 1. **Correcting journalistic terminology and media stereotypes** (17:24) — Tactical approaches to addressing unhelpful corporate imagery and inaccurate terminology in journalism. 1. **The systemic lack of vulnerability disclosure policies** (23:01) — The chilling effect on security research caused by inadequate corporate reporting frameworks. 1. **Reforming anti-hacking legislation to protect ethical research** (24:03) — Why current legal frameworks penalize security professionals and require urgent legislative reform. 1. **Engaging local officials to advocate for legislative reform** (28:36) — Actionable ways to contact representatives and build momentum for updated legal protections. 1. **Implementing effective corporate vulnerability disclosure policies** (29:23) — Best practices for creating clear reporting frameworks that foster trust with security researchers. 1. **Volunteering to support grassroots advocacy for the hacker community** (32:16) — Opportunities to contribute time and resources to groups defending security researcher rights. 1. **Discussing terminology variations and corporate lobbying influences** (33:44) — Addressing questions on preferred nomenclature and the barriers big tech places on legal reform. ## Related Moments - [Exploring pathways to application security careers and research workflows](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) (from "Stranger Danger: Your Java Attack Surface Just Got Bigger") - [Attacker motivations and the right to repair movement](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) (from "Cyber Security: Small, and Large!") - [Identifying non-coding software vulnerabilities and organizational risks](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) (from "Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?") - [Establishing blameless dialogue surrounding critical software security vulnerabilities](https://www.wearedevelopers.com/videos/1293-the-weekly-developer-show-boosting-python-with-cuda-css-updates-navigating-new-tech-stacks) (from "The weekly developer show: Boosting Python with CUDA, CSS Updates & Navigating New Tech Stacks") - [Fear as a critical security and information vulnerability](https://www.wearedevelopers.com/videos/1998-from-code-to-culture-why-leadership-determines-software-quality) (from "From Code to Culture: Why Leadership Determines Software Quality") - [Introduction to security advocacy and automation testing](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) (from "WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio** - [Senior Software Engineer](https://www.wearedevelopers.com/jobs/ext/15942-senior-software-engineer) at **GitHub** - [Senior Software Engineer, Fraud](https://www.wearedevelopers.com/jobs/ext/1280398-senior-software-engineer-fraud) at **Twilio** - [Senior Security Engineer, Incident Response](https://www.wearedevelopers.com/jobs/ext/1347114-senior-security-engineer-incident-response) at **Twilio**