Belgium is unsafe for CVD (floort.net)
from Pro@programming.dev to cybersecurity@infosec.pub on 06 Jul 20:03
https://programming.dev/post/33467122

#cybersecurity

threaded - newest

0xThiebaut@infosec.pub on 07 Jul 07:01 collapse

“Unsafe” might be an unfair statement. Afaik, Belgium is one of the few countries with actual CVD laws which protect researchers if you abide by the rules. Plenty of other EU countries have no guidelines and are pretty much “fuck around and find out”. Sure, you might not like the CVD requirements because you’d prefer to publish everything, but in several countries you would get prosecuted just for finding the vulnerability.

As a Belgian, I’m proud we have the CVD law. I would definitely prefer it having less constraints on the reporters but the law has to find some balance with victims who would otherwise not support any CVD at all.

On the several deadlines, I have yet to hear about any form of prosecution for failure to meet these.