Skip to content

Rules Change Request: Mandatory minimum good-faith safe harbor commitment in CNA disclosure policies #52

Description

@boblord

Rules Change Request: Mandatory minimum good-faith safe harbor commitment in CNA disclosure policies

Section affected: 3.2.6 (CVE ID Assignment and Vulnerability Disclosure), specifically 3.2.6.1 through 3.2.6.3

Current text:

3.2.6 The CVE Program itself does not follow or require a specific Vulnerability disclosure policy. CNAs and other CVE Program participants operate under a variety of Vulnerability disclosure policies.

3.2.6.3 CNAs MAY require CVE ID assignment to be made using specific processes or mechanisms. Such processes or mechanisms MUST NOT conflict with the CNA Operational Rules.

Problem: 3.2.6.1 and 3.2.6.2 require every CNA to publish guidance on how it assigns CVE IDs within the context of Vulnerability disclosure, and to provide a URL to that policy. Nothing requires the content of that policy to protect a good-faith researcher who reports a vulnerability. Legal exposure, response time, and embargo handling for a reporter are entirely CNA-dependent, and 3.2.6 states plainly that the Program itself doesn't follow or require a specific disclosure policy, leaving no floor.

This is not a hypothetical gap. Genuine safe harbor commitments remain the exception rather than the norm even among large, well-resourced organizations with no shortage of legal sophistication to draft one. disclose.io's public directory at state.disclose.io, built on the open, CC0-licensed diodb directory, grades disclosure programs and policies against its open-source diostatus maturity model, and lets anyone check a given organization's status directly. Voluntary discretion has had a long runway, more than seven years since disclose.io's 2018 launch, and adoption has plateaued well short of universal, which is precisely the condition under which a rules-level floor becomes necessary rather than aspirational.

Proposed change: Add 3.2.6.6:

A CNA's published Vulnerability disclosure policy MUST include, at minimum, the following commitments to a good-faith Vulnerability reporter: (1) an authorization of good-faith security research consistent with the CNA's published reporting process, together with a waiver of the CNA's own legal claims, including under computer-crime, anti-circumvention, and terms-of-service laws or their non-US equivalents, arising from research activity that falls within that authorization; (2) a defined maximum response time within which the CNA MUST acknowledge receipt of a report; (3) a defined maximum embargo period after which the CNA MUST either publish a CVE Record or provide the reporter a documented, substantive justification for continued non-disclosure; and (4) a public escalation path the reporter MAY use if the CNA becomes unresponsive, consistent with 4.6. A CNA satisfies clause (1) by adopting an open, community-maintained safe harbor template, such as the disclose.io Safe Harbor terms, or terms substantially similar to such a template, rather than drafting bespoke legal language.

Amend 3.2.6.3 to read:

CNAs MAY require CVE ID assignment to be made using specific processes or mechanisms. Such processes or mechanisms MUST NOT conflict with the CNA Operational Rules, and MUST NOT conflict with the minimum good-faith reporter protections required under 3.2.6.6.

Rationale: Gives every good-faith reporter a uniform baseline of protection instead of one that depends entirely on which CNA they happen to be dealing with. Ties the Program's existing publication requirement (3.2.6.1, 3.2.6.2) to substantive minimum content rather than leaving the content entirely to each CNA's discretion.

Clause (1) is framed as authorization plus waiver rather than a blanket prohibition on legal action, because a CNA cannot categorically promise not to pursue legal action for conduct outside the scope of good-faith research it has actually authorized, and counsel reviewing a bare "MUST NOT pursue legal action" commitment would reasonably read it as an uncontrolled rights waiver. The authorization-plus-waiver construction is the version that survives legal review in practice; it has direct lineage to the safe harbor language most modern vulnerability disclosure programs use, tracing back to Dropbox's 2018 safe harbor commitment, and is the same construction standardized in the open-licensed disclose.io terms. Permitting compliance via an existing open template, rather than requiring each CNA's counsel to draft bespoke language from scratch, turns adoption from a legal-drafting burden into a low-effort copy-paste, which is more likely to produce actual uniform protection than a rule that leaves every CNA solving the same problem independently.

The rule deliberately does not have the Program specify fixed numeric values for the response-time or embargo maximums in clauses (2) and (3), leaving each CNA to publish its own, consistent with the existing structure of these rules, which generally sets requirements rather than specific durations. If a fixed anchor is wanted for reference, ISO/IEC 29147 and the CERT/CC 45-day disclosure norm are established points of comparison. A defined maximum embargo is also not purely aspirational: mechanisms already exist, such as timelock encryption that enforces publication at a deadline independent of the discloser's cooperation, that make an embargo commitment enforceable as a mechanism rather than a promise, which is the direction the ecosystem is already moving regardless of what the CNA Operational Rules require.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions