Quantifying the Pressure of Legal Risks on Third-party Vulnerability Research
Alexander Gamero-Garrido, Stefan Savage, Kirill Levchenko, Alex C. Snoeren
Abstract
Product vendors and vulnerability researchers work with the same underlying artifacts, but can be motivated by goals that are distinct and, at times, disjoint. This potential for conflict, coupled with the legal instruments available to product vendors (e.g., EULAs, DMCA, CFAA, etc.) drive a broad concern that there are "chilling effects" that dissuade vulnerability researchers from vigorously evaluating product security. Indeed, there are well-known examples of legal action taken against individual researchers. However, these are inherently anecdotal in nature and skeptics of the chilling-effects hypothesis argue that there is no systematic evidence to justify such concerns. This paper is motivated by precisely this tussle. We present some of the first work to address this issue on a quantitative and empirical footing, illuminating the sentiments of both product vendors and vulnerability researchers. First, we canvas a range of product companies for explicit permission to conduct security assessments and thus characterize the degree to which the broad software vendor community is supportive of vulnerability research activities and how this varies based on the nature of the researcher. Second, we conduct an online sentiment survey of vulnerability researchers to understand the extent to which they have abstract concerns or concrete experience with legal threats and the extent to which this mindset shapes their choices.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d0e87f88-8133-4454-80d5-e598c1af4386Cited by top-tier papers6
- RepliCueAuth: Validating the Use of a Lab-Based Virtual Reality Setup for Evaluating Authentication SystemsFlorian Mathis, Kami Vaniea, Mohamed KhamisCHI 2021 · 52 citations
- Security Certification in Payment Card Industry: Testbeds, Measurements, and RecommendationsSazzadur Rahaman, Gang Wang, Danfeng Daphne YaoCCS 2019 · 31 citations
- Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy ResearchFlorian Hantke, Sebastian Roth, Rafael Mrowczynski, Christine Utz et al.S&P 2024 · 17 citations
- Engaging Company Developers in Security Research Studies: A Comprehensive Literature Review and Quantitative SurveyRaphael Serafini, Stefan Albert Horstmann, Alena NaiakshinaUSENIX Security 2024 · 7 citations
- "Sticking their heads out above the parapets": Lived Experiences of Legal Risks in ResearchSunoo Park, Daniel R. ThomasUSENIX Security 2026
Related papers
- "Abuse Risks are Often Inherent to Product Features": Exploring AI Vendors' Bug Bounty and Responsible Disclosure PoliciesYangheran Piao, Jingjie Li, Daniel W. WoodsUSENIX Security 2026 · 1 citation
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin et al.S&P 2025
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- "All of them claim to be the best": Multi-perspective study of VPN users and VPN providersReethika Ramesh, Anjali Vyas, Roya EnsafiUSENIX Security 2023
- Confusing Value with Enumeration: Studying the Use of CVEs in AcademiaMoritz Schloegel, Daniel Klischies, Simon Koch, David Klein et al.USENIX Security 2025
