Reciprocal Disclosure and the Ethics of Vulnerability Reporting: A Cybersecurity Ethics Case Study of Nightmare Eclipse
Authors/Creators
Description
Bug bounty programs and coordinated vulnerability disclosure (CVD) frameworks are widely regarded as means of aligning the interests of independent security researchers with that of software vendors. This paper argues that the ethical sustainability of these frameworks depends not on their formal structure but on the quality of moral give-and-take (reciprocity) between researcher and organization. Drawing on Cialdini's (2006) principle of reciprocity, Fricker's (2007) concept of epistemic injustice, and the existing ethics of disclosure literature, this paper examines the case of Nightmare Eclipse - a security researcher who shifted from cooperative disclosure to publicly releasing a series of zero-day exploits targeting Microsoft Windows, including core components such as Windows Defender and BitLocker, after experiencing what they describe as systemic dismissal, undervaluation, and legal intimidation.
The case is notable for its scale, as three of the first six disclosed vulnerabilities were exploited in the wild, attackers were able to chain them with ransomware deployments, and the researcher's GitHub and GitLab accounts were swiftly suspended in what can only be described as an institutional effort to suppress further disclosure. These were not vulnerabilities in a niche product either - Windows runs on over 1.4 billion active devices worldwide (Mehdi, 2025), dominates the global desktop market (StatCounter, 2026) and serves as the backbone of most enterprise IT environments - meaning the fallout affected businesses, hospitals, governments and critical infrastructure that depend on it every day.
The argument is that this case exposes a structural failure - and a form of epistemic injustice - in how organizations conceive of their moral obligations toward vulnerability reporters and that the resulting harm to end users, enterprises and the broader international security environment constitutes a foreseeable consequence of institutional bad faith. The paper proposes a normative framework focused on the concept of reciprocal disclosure - a reframing that puts the same expectations on both sides and accounts for the fact that the researcher and the organization do not hold equal power in this relationship.
Files
Herrick_2026_Reciprocal_Disclosure.pdf
Files
(299.9 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:20d6183137463528f4b67de56a2d77d5
|
299.9 kB | Preview Download |
Additional details
Related works
- Is identical to
- Preprint: https://dudetechitout.com/papers/Herrick_2026_Reciprocal_Disclosure.pdf (URL)
- Preprint: https://philpapers.org/rec/HERACE-6 (URL)
- Preprint: https://www.researchgate.net/publication/408180150_Reciprocal_Disclosure_and_the_Ethics_of_Vulnerability_Reporting_A_Cybersecurity_Ethics_Case_Study_of_Nightmare_Eclipse (URL)