Brutkey

Martin Seeger
@masek@infosec.exchange

【How to handle a responsible disclosure you get from me?】


Let’s assume you run an IT service or deliver some kind of device to customers, and you receive a report from me informing you about a security problem in your service or device. This can —and has—happened to some of the best in the industry. So, you're not alone.

Now you're wondering: What should you do with this disclosure?

Rejoice: This post is here to guide you through the process.

1/9