Compass at the Digital Investigations Conference

Cyrill Brunschwiler, Managing Director at Compass Security Schweiz

AG, spoke on consumer electronics patch cycles, responsible vulnerability

disclosure processes and incident handling at the annual Digital

Investigations Conference in Rueschlikon/Zurich.

The talk covered a real story on how a trivial bug in a DSL router turned
into a vendor’s nightmare. The nightmare penultimately resulting in negative
press coverage, involving the Swiss MELANI/GovCERT, and finally attracting
the US Federal Trade Commision (FTC) to investigate into the case. The talk
was not only about how the vulnerability was disclosed and handled, but
provides details on the serious discoveries that came with it and some take
aways - for all bug hunters, incident handlers and vendors.