Question

What is responsible disclosure, and how do bug bounties work?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Responsible disclosure is reporting a security vulnerability to the affected organisation first, giving them time to fix it before details become public. A bug bounty programme is the formalised, paid version — and the distinction between them matters legally as much as practically.

Why coordination exists at all. Publishing a vulnerability immediately gives attackers a working exploit against unpatched systems. Never publishing removes the pressure to fix and leaves users unable to assess their own risk. Coordinated disclosure is the compromise: report privately, agree a timeline, publish afterwards.

How it usually runs:

Find the policy. Look for a security.txt file, a security page, or a bounty platform listing. This establishes what is authorised.

Report privately, with clear reproduction steps, impact assessment and proof of concept — and no more access than needed to demonstrate it. Downloading a database to prove you could is where researchers get into serious trouble.

Agree a timeline. Ninety days is the common default, with extensions for genuinely complex fixes and shortening if the issue is being exploited.

Coordinate publication, often with a CVE identifier and credit to the reporter.

How bounties differ: they define scope precisely — which domains and systems are in and out — set severity-based payment tiers, and, crucially, provide a safe harbour statement undertaking not to pursue legal action for good-faith research within scope.

Why the legal position matters. Computer misuse laws in many countries criminalise unauthorised access with no research exemption. Researchers acting in good faith have faced prosecution and legal threats. A published policy with safe harbour is what converts an offence into authorised testing — so read the scope, and stay inside it.

For organisations: publish a security contact even with no bounty; acknowledge reports quickly, since silence is the commonest reason researchers go public; never threaten a good-faith reporter, which is reputationally disastrous; and give credit, which is frequently valued as much as payment.

General information, not legal advice.

Related Questions