Yolan Romailler: A “Dead Man’s” Responsible Disclosure System
A DEF CON 30 talk introducing a new model of responsible disclosure based on timelock encryption — where a vulnerability report is encrypted in such a way that it cannot be decrypted until a predefined moment in the future.
The concept, first discussed on the Cypherpunks mailing list in 1993, is implemented here as an open-source tool with strong cryptographic security guarantees. The solution relies on threshold cryptography and the decentralized League of Entropy network, which operates a public randomness beacon.
The system ensures automatic full disclosure of a vulnerability report once the patch window expires — without requiring further action from the researcher and without relying on informal “Twitter SHA256 commitments.”
The concept, first discussed on the Cypherpunks mailing list in 1993, is implemented here as an open-source tool with strong cryptographic security guarantees. The solution relies on threshold cryptography and the decentralized League of Entropy network, which operates a public randomness beacon.
The system ensures automatic full disclosure of a vulnerability report once the patch window expires — without requiring further action from the researcher and without relying on informal “Twitter SHA256 commitments.”