Skip to content

Hack Atlas · ATLAS / SEC-02 · Defensive Cybersecurity

The Disclosure That Strengthened the Product

Responsible disclosure turns a found weakness into a safer system — if the organisation can receive the news without theatre.

A vulnerability is a fact about a system. The ethics are in the path you take after you see it. HACKERS studies the receiving function — not the trophy.

File
ATLAS / SEC-02
Domain
Defensive research
Framework
Receiving function
Studio
30 min studio
Stance
Educational / defensive

Fig. 00 — Receiving function — signature diagram

FINDRECEIVEPATCHPUBLISHTHE VULNERABILITY IS A FACT. THE ETHICS ARE THE PATH.

00 / Abstract

Software contains defects. Independent researchers find some of them. Vendors, users, and attackers share a clock. The path from discovery to patch is a social system, not only a technical one.

Coordinated vulnerability disclosure — report privately, give time to patch, then publish the class of error — converts adversarial knowledge into product improvement. Bug bounty programmes industrialise that loop when they are competent, and theatre when they are not.

HACKERS studies the receiving function: a way to report, a clock, a patch path, and credit without prosecution for good-faith research. Skip it and you get silence, rumours, or harm. We do not teach unauthorised access or operational exploitation.

Finding a weakness is not permission to use it. Authorisation, scope, and a competent receiving function are the line.

01 / Classification

This is not a hacking story. It is a social-system story with a clock.

Software contains defects. Independent researchers find some of them. Vendors, users, and attackers share a clock. The path from discovery to patch is a social system, not only a technical one.

02 / Hidden frame

Talking about a weakness is not the same as using it.

Organisations still treat a researcher as a threat because the knowledge looks like a weapon. Knowledge is a fact. A weapon is a path. Confusing them is how you prosecute the messenger and keep the defect.

A receiving function is boring on purpose: a contact, a scope, a clock, a patch, a public class of error, a regression test. Boring is how adults handle dangerous facts.

HACKERS will not publish exploit steps. We will ask whether anyone would know where to send the letter, and what happens in the first 24 hours.

03 / Five false objects

Name the false object, then drop it.

  1. C1

    Disclosure is attack

    Speaking was treated as using.

    A fact and a path are different objects. Ethics live in the path.

  2. C2

    Secrecy is security

    Silence as a strategy.

    Silence without a receiving function is how rumours become harm.

  3. C3

    Bounty is a PR page

    A dollar figure without a clock.

    A programme is a receiving function or it is theatre.

  4. C4

    Legal as a weapon

    Good-faith research met a solicitor.

    Credit without prosecution is how you keep researchers inside the loop.

  5. C5

    Patch is the end

    A silent fix, no class shared.

    The industry needs the class of error, not your trophy screenshot.

04 / The system

What actually sat on the table.

Talking about a weakness is equivalent to using it. Security is a secret, so researchers should stay quiet or be treated as threats.

The clock is shared with people who did not volunteer to be in your experiment. That is why HACKERS forbids operational write-ups and requires a receiving function as the object of study.

Find → report in scope → patch → disclose class → harden regression tests. Skip receive and the chain becomes silence, rumour, or harm. Only one of those is our work, and it is the first.

05 / The costume of the bounty page

Do not study the outfit.

A dollar figure on a marketing site is a costume. So is a dark-mode hall of fame. The interesting object is whether a report would be read tonight.

If the case study stops at ‘they paid researchers’, you have a press release. The studio begins when the first 24 hours are a designed object.

Coordinated vulnerability disclosure — report privately, give time to patch, then publish — converts adversarial knowledge into product improvement. Bug bounty programmes industrialise that loop when they are competent.

06 / The chain

FINDFACTRECEIVEINBOXCLOCKPATCHPUBLISHCLASSREGRESSTESTSCOPE AND HARM-REDUCTION LIVE HERE — NOT IN A TROPHY SHOT
Fig. 01 — From find to a stronger product

Fig. — Toughness theatre versus learning loop

Silent fortress

Looks strong. Facts go elsewhere.

PR bounty

Looks mature. Inbox is a void.

Inbox, no class

You patch. The field stays blind.

Receive, clock, class, regress

The only cell that strengthens the product.

Fig. 02 — Apparent toughness versus actual learning

S0 No contact

tough 80 / learn 10

S1 PR bounty

tough 90 / learn 25

S2 Inbox, no clock

tough 60 / learn 40

S3 Clock + patch

tough 50 / learn 75

S4 Class published

tough 40 / learn 88

S5 Regression

tough 45 / learn 95

The fact cannot silently return.

Fig. 03 — Receiving-function axioms

  1. R1

    Fact ≠ path

    A vulnerability is a fact. Using it is a different act, and out of scope here.

  2. R2

    Contact is a product

    security@, a scope page, a human who answers.

  3. R3

    Clock is a control

    Time-to-patch is part of the design, not a mood.

  4. R4

    Credit without prosecution

    Good-faith, in-scope research is how you buy the next report.

  5. R5

    Publish the class

    A silent patch trains only you. A class trains the field.

If a researcher would not know where to write, you do not have a security programme. You have a vibe.

Fig. 04 — Four planes of coordinated disclosure

P1 Find

In-scope, authorised, no harm.

Trophy hunting outside the brief.

P2 Receive

Inbox, triage, human.

A black hole with a logo.

P3 Patch

Fix, clock, regression.

A silent hotfix nobody can learn from.

P4 Public

Class of error, credit, no recipe.

Either silence or a how-to.

10 / Failure taxonomy

Failure taxonomy and corresponding defences
IDFailureWhat brokeControl
F1No front doorResearchers could not find a contact.Publish security.txt, a scope, a human.
F2Legal ambushA good-faith report met a threat.Safe-harbour language for in-scope research.
F3Clockless inboxReports aged in a queue.SLAs as product. Triage is a control.
F4Patch without classOnly one vendor learned.Publish the pattern. Not the payload.
F5Bounty theatreMarketing ran the programme.Engineering owns receive, patch, regress.
F6Recipe leakWrite-ups that teach operational harm.HACKERS rule: class and defence, never steps to copy.
Fig. — Failures and the controls that match them

The same join in other systems

Aviation safety reports

A near-miss inbox that does not prosecute the reporter.

Learning requires a receiving function with amnesty for good faith.

Medicine incident reports

A fact about a system, not a hunt for a villain.

If reporting is punished, the next fact goes underground.

Whistleblowing channels

A fact with a clock and a harm path.

Scope and protection are the product.

Open-source advisories

CVE as a class, not a tutorial.

The field needs the pattern. Users need a patch. Attackers do not need a recipe from us.

A trusted receiving function inside the organisation: a way to report, a clock, a patch path, and credit without prosecution for good-faith research.

Find → report in scope → patch → disclose → harden regression tests. Skip the receiving function and you get silence, rumours, or harm.

Defence as architecture

  1. 01 Front door

    security.txt, scope, a mailbox that is read.

  2. 02 Safe harbour

    Good-faith, in-scope research is not a prosecution.

  3. 03 Clock

    Triage and patch times as published product.

  4. 04 Patch

    Fix the instance. Then the class.

  5. 05 Publish class

    Teach the pattern. Do not teach operational harm.

  6. 06 Regress

    A test that fails if the fact returns.

Before — fortress theatre

  • No public contact.
  • Researchers treated as attackers.
  • Silence as strategy.
  • Patch maybe, class never.
  • Bounty as a marketing page.

After — receiving function

  • security.txt and a human.
  • Safe harbour for in-scope good faith.
  • A clock everyone can see.
  • Patch plus class, never a recipe.
  • Engineering-owned loop with regression tests.

Second-order system

  1. R0 Fact

    Someone sees a weakness.

  2. R1 Path choice

    Report, rumour, or harm. HACKERS only studies report.

  3. R2 Inbox

    The organisation can or cannot receive.

  4. R3 Users

    The clock is shared with people who did not volunteer.

  5. R4 Field

    The class is or is not taught.

  6. R5 Trust

    Researchers decide whether to write to you next time.

Typical brief versus HACKERS studio
TopicTypical briefHACKERS studio
SecurityTools and CTF.The social system after the find. No operational how-to.
LawCFAA horror stories.Safe harbour as a product requirement.
ProductShip, then harden.A receiving function is a feature of v1.
CommsHold the story.Publish the class. Kill the recipe.
EthicsA slide.Authorise / Test / Improve as operating law.
Fig. — The join lives between chairs

15 / What the brief missed

Elite programmes still stop at the object.

Computer security courses still over-index on finding and under-index on receiving. Law courses over-index on liability. Journalism over-indexes on the leak. The receiving function sits between them, so organisations fake a bounty page and call it maturity.

HACKERS trains the loop. SCAN whether a stranger could report. FLIP the idea that speech is use. BUILD an inbox with a clock. BREAK it with a 24-hour drill. PROVE a class write-up that contains no recipe.

HACKERS studies this as defence. Finding a weakness is not permission to use it. Authorisation, scope, and harm-reduction are the line.

16 / Design studio

Do not admire the turning point. Redesign the join.

If a researcher found a serious flaw in your product tonight, who would they email — and what would happen in the first 24 hours?

  1. Exercise A

    If a researcher found a serious flaw in your product tonight, who would they email?

  2. Exercise B

    Write the first 24 hours as a runbook. Names, not departments.

  3. Exercise C

    Draft safe-harbour language for in-scope, good-faith research.

  4. Exercise D

    Write a class-of-error disclosure with zero operational detail.

  5. Exercise E

    Add the regression test that would fail if the fact returned.

Interrogate the join

Can a stranger find a contact in two minutes?

If not, you are selecting for rumours.

48-hour authorised studio

  1. 0–8h

    Door

    security.txt, scope page, named owner.

  2. 8–20h

    24h

    Runbook for the first day. No theatre.

  3. 20–36h

    Harbour

    Legal language that keeps good faith inside the loop.

  4. 36–48h

    Class

    A sample advisory with zero operational detail. Present the loop.

Anti-patterns

  • Treat a report as an attack.
  • Publish a bounty and staff it with marketing.
  • Let reports rot without a clock.
  • Silent patch, no class.
  • Write-ups that are recipes. HACKERS will not.

19 / The transferable lesson

A vulnerability is a fact about a system. The ethics are in the path you take after you see it.

Publish a clear security contact. Define scope. Do not punish good-faith reports. Patch, then share the class of error so others can hunt it in their own systems.

Questions we are asked

Does HACKERS teach how to find and use vulnerabilities?
No. We teach how a system should receive a fact, patch it, and share the class. Authorise / Test / Improve.
What is a receiving function?
Contact, scope, clock, patch, class, regression, and safe harbour for good-faith in-scope research.
Are bug bounties enough?
Only if engineering owns the loop. A dollar figure is a costume.
Should every issue be public immediately?
No. Users share a clock. Coordinate, patch, then publish the class — not a tutorial.
Why is this in the Atlas?
Because the hidden rule is social. Technical talent without a receiving function still produces harm.

Public sources

Cited for classification and method. Not as a manual. Atlas cases are educational and defensive.