Ledger CTO Calls for Adherence to Responsible Vulnerability Disclosure Principles
Charles Guillemet, the Chief Technology Officer (CTO) of Ledger, has urged the hardware wallet industry to adhere to the principles of 'responsible vulnerability disclosure.' He pointed out that the ease of discovering vulnerabilities with AI could increase risks for users if disclosures are made hastily. CTO Guillemet emphasized the importance of a 'coordinated disclosure' process, where manufacturers are informed unofficially, a deadline for fixes is set, and vulnerabilities are disclosed jointly. He criticized some actors for immediately disclosing vulnerabilities, creating unnecessary panic. Such actions could lead users to abandon self-custody, he warned. He requested users to keep their software up to date and follow basic security protocols, while encouraging researchers to report vulnerabilities through official channels. It has been reported that several organizations agreed to adopt coordinated disclosure as an industry principle. Ledger refuted claims that it had not fixed the flaws raised by TestMachine before they were disclosed, and Guillemet's remarks seem to have broadened the debate to issues affecting the entire hardware wallet industry.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

DEEPCOIN Completes System Penetration Testing with HackenProof to Strengthen Asset Security

Trezor and BitBox warn users of phishing emails exploiting STM32 vulnerability alert

Public Salaries Drop 40.5% Under Milei, Police and Military Most Affected

Phishing Emails Impersonating BPI Employees Distributed, Official Domain is 'btcpolicy.org'

XRP Healthcare Ceases Operations, XRPH and XRPHAI Tokens to be Delisted

Empowa DeFi Platform Reports Theft of 143,710 ADA and 4,240,000 EMP

Loans up to 1 billion UAH, state property rental, and business security

Marchenko Warns of Funding Shortages and Salary Delays

New Cryptocurrency Law in Poland, Strengthening Control of Authorities

Two Teachers from Ussuriysk Lost Over 2 Million Rubles in Fake Crypto Investments

Houthi Forces Take Control of Mocha Port, Increasing Risks for Red Sea Shipping

New Underground Money Laundering Scheme Using Virtual Currency, Seven Sentenced

PinGo Announces Contract Upgrade to Enhance Security

Anthropic Confirms Claude Model Cybersecurity Incident, Reveals Bias Reasoning and Recklessness Issues

Fake Security Email Targets Trezor Users

Strategy Signs MOU with Naver Cloud for AI Innovation

California Governor Signs AI Safety Bills to Regulate Third-Party Security Assessment Mechanisms

DSRV Integrates Canton Coin Custody Service

Bithumb Warns Against Fake AI Trading Malware

Bitcoin Mining Farm Dismantled in Puebla, Mexico

Solana Foundation Joins Rust Foundation as Platinum Member

Citrea Suspends Cross-Chain Transfers of ctUSD and Other Assets Due to Zentra Finance Security Incident

National Energy and Climate Plan Achieved 59% Completion

BitcoinHabebe Questions Trust Wallet Security, Emphasizes WEEX Safety Guarantee

Ledger Appoints Oded Blatman as Chief Information Officer and Chief Security Officer

Algorand Appoints William Herkelrath as New CEO

Solar Power Plant Launched at Chernobyl Nuclear Power Plant with Capacity of 2 MW

22-Year-Old Malone Lam Admits to $245 Million Crypto Heist

Safe to Launch 'Safe Pro' on October 6




