World Congress 2021 • Jun 28, 2021

We Deserve Rights

Chloé Messdaghi

Security researchers are routinely punished for making software safer. One in four ethical hackers now refuses to report critical bugs. It is time to demand legal rights.

Pause
Mute Enter Fullscreen
#1 about 4 min

Grassroots advocacy for security researcher rights

Exploring the movements working to protect hackers and change public perception.

#2 about 2 min

Understanding the difference between hackers and attackers

How intent separates ethical security researchers from malicious threat actors.

#3 about 5 min

The legal risks of reporting corporate vulnerabilities

A real-world case study of a security researcher facing a lawsuit for reporting a bug.

#4 about 9 min

Challenging socially constructed fears around the hacker community

How subconscious biases and social norms shape negative legal and public perceptions.

#5 about 6 min

Correcting journalistic terminology and media stereotypes

Tactical approaches to addressing unhelpful corporate imagery and inaccurate terminology in journalism.

#6 about 2 min

The systemic lack of vulnerability disclosure policies

The chilling effect on security research caused by inadequate corporate reporting frameworks.

#7 about 5 min

Reforming anti-hacking legislation to protect ethical research

Why current legal frameworks penalize security professionals and require urgent legislative reform.

#8 about 1 min

Engaging local officials to advocate for legislative reform

Actionable ways to contact representatives and build momentum for updated legal protections.

#9 about 3 min

Implementing effective corporate vulnerability disclosure policies

Best practices for creating clear reporting frameworks that foster trust with security researchers.

#10 about 2 min

Volunteering to support grassroots advocacy for the hacker community

Opportunities to contribute time and resources to groups defending security researcher rights.

#11 about 8 min

Discussing terminology variations and corporate lobbying influences

Addressing questions on preferred nomenclature and the barriers big tech places on legal reform.

Matching moments

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:32 min

Attacker motivations and the right to repair movement

Martin Schmiedecker · LIVE

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · World Congress 2023

3:55 min

Establishing blameless dialogue surrounding critical software security vulnerabilities

Chris Heilmann Chris Heilmann +2 · LIVE

2:33 min

Fear as a critical security and information vulnerability

Oskar Kruschitz Oskar Kruschitz · Europe 2026 Virtual

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE