{"id":16145,"date":"2019-07-11T04:57:22","date_gmt":"2019-07-11T08:57:22","guid":{"rendered":"https:\/\/www.kaspersky.co.in\/blog\/kaspersky-joins-disclose-io\/16145\/"},"modified":"2022-05-04T22:10:01","modified_gmt":"2022-05-04T16:40:01","slug":"kaspersky-joins-disclose-io","status":"publish","type":"post","link":"https:\/\/www.kaspersky.co.in\/blog\/kaspersky-joins-disclose-io\/16145\/","title":{"rendered":"Building trust together with Disclose.io"},"content":{"rendered":"<p>Why did you buy this antivirus and not that one? <s>Because this one costs less<\/s> Because you trust it more, of course. And why do security researchers spend more time analyzing this app and not that one? Because they trust the company that developed the first app more. Not all businesses welcome news about vulnerabilities being found in their products \u2014 some actually threaten the researchers with legal action.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/36\/2019\/07\/11152916\/kaspersky-blog-default-featured.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/36\/2019\/07\/11152916\/kaspersky-blog-default-featured.jpg\" alt=\"\" width=\"1460\" height=\"960\" class=\"aligncenter size-full wp-image-16155\"><\/a><br>\nSo, yes, in general, choosing a product or company is about trust. One mistake is enough to ruin the trust, but building it is significantly harder. It\u2019s like a tower consisting of thousands of bricks \u2014 removing one brick may be enough for the tower to collapse, but to build the tower, you need to carefully lay one brick next to another several thousand times. That\u2019s hard and time-consuming.<\/p>\n<h2>A safe harbor for researchers<\/h2>\n<p>We at Kaspersky want you, our customers and potential customers, to trust us, so we are building that tower, brick by brick, and maintaining it. We\u2019ve already launched our <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/transparency-status-updates\/23637\/\" rel=\"noopener noreferrer nofollow\">Global Transparency Initiative<\/a>. We hope that shows how transparent our business is. And we\u2019ve increased our <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/even-more-transparency\/19943\/\" rel=\"noopener noreferrer nofollow\">bug bounties<\/a>. Now we are pleased to announce that we have joined Bugcrowd\u2019s <a target=\"_blank\" href=\"https:\/\/www.disclose.io\/\" rel=\"noopener noreferrer nofollow\">Disclose.io<\/a> project to guarantee that we also won\u2019t be legally assaulting those who look to research our products and find vulnerabilities in there.<\/p>\n<p>Bugcrowd launched Disclose.io in partnership with renowned security researcher Amit Elazari in August 2018 to provide a clear legal framework to protect organizations and researchers engaged in bug bounty and vulnerability disclosure programs<em>. <\/em>Basically, what Disclose.io offers is a set of agreements between researchers and businesses. All companies who have joined Disclose.io agree to follow these agreements, and so do all of the researchers. These agreements are very simple. They\u2019re easy to read and understand \u2014 forget about the hundreds of subsections and small fonts here and there that can make legal agreements nearly impossible to process. You can find the core terms <a target=\"_blank\" href=\"https:\/\/github.com\/disclose\/disclose\/blob\/master\/core_terms\" rel=\"noopener noreferrer nofollow\">on GitHub<\/a>, and that adds to their transparency; documents on GitHub cannot be modified without the entire community seeing this fact.<\/p>\n<p>These agreements encourage businesses not to punish researchers for their research, but to work with them to understand the vulnerability and fix it, and to recognize their contribution to the security of the product. On the other hand, these agreements require researchers to be responsible with the vulnerabilities they find \u2014 not to make information public before the issue is fixed, not to abuse the data they access, not to extort money from the vendors, and so on and so forth.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/36\/2019\/07\/11151706\/disclose-io-logo.png\"><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/36\/2019\/07\/11151706\/disclose-io-logo.png\" alt=\"\" style=\"max-width:240px;margin:40px auto;\" class=\"aligncenter size-medium wp-image-27590\"><\/a><\/p>\n<p>To sum it up, Disclose.io basically says: \u201cDear researchers and businesses, if you both behave nicely, it will be beneficial for both of you.\u201d We absolutely agree with that statement, and that\u2019s why we\u2019re supporting Disclose.io movement and providing a safe harbor for researchers that want to find weak spots in our products.<\/p>\n<p>Our customers, of course, will benefit as well. The more a product or service is looked into by the security community, the more secure it becomes. For security solutions, being as secure as possible is certainly a must.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-top3\">\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky joins the Disclose.io project to offer safe harbor for security researchers.<\/p>\n","protected":false},"author":2706,"featured_media":16170,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2195],"tags":[1571,2787,28,2247],"class_list":{"0":"post-16145","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-special-projects","8":"tag-bug-bounty","9":"tag-disclose-io","10":"tag-kaspersky","11":"tag-transparency"},"hreflang":[{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/kaspersky-joins-disclose-io\/16145\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/kaspersky-joins-disclose-io\/13655\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/kaspersky-joins-disclose-io\/18041\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/kaspersky-joins-disclose-io\/16179\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/kaspersky-joins-disclose-io\/14934\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/kaspersky-joins-disclose-io\/18860\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/kaspersky-joins-disclose-io\/17608\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/kaspersky-joins-disclose-io\/23101\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/kaspersky-joins-disclose-io\/6134\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/kaspersky-joins-disclose-io\/27588\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/kaspersky-joins-disclose-io\/11957\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/kaspersky-joins-disclose-io\/12151\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/kaspersky-joins-disclose-io\/10968\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/kaspersky-joins-disclose-io\/19694\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/kaspersky-joins-disclose-io\/23601\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/kaspersky-joins-disclose-io\/24012\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/kaspersky-joins-disclose-io\/18675\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/kaspersky-joins-disclose-io\/22963\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/kaspersky-joins-disclose-io\/22902\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.co.in\/blog\/tag\/transparency\/","name":"transparency"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/16145","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/users\/2706"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/comments?post=16145"}],"version-history":[{"count":11,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/16145\/revisions"}],"predecessor-version":[{"id":20189,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/posts\/16145\/revisions\/20189"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/media\/16170"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/media?parent=16145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/categories?post=16145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.co.in\/blog\/wp-json\/wp\/v2\/tags?post=16145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}