THE DISCLOSURE WARS

A running, decades-long argument over one question: who decides which security flaws you are allowed to hear about — the researcher who found the bug, or the vendor's lawyers who would rather you didn't? The recurring answer, in courtroom after courtroom, is that corporate counsel keeps trying to be the boss of the disclosure debate. They have torn pages out of conference binders, destroyed the CDs, jailed a Russian programmer over an e-book cracker, gagged MIT students the night before a talk, and sued a startup for defamation over a pacemaker flaw the FDA later confirmed. Sometimes the researcher broke an NDA. Almost every time, the flaw was real.

They had to do what’s right for their shareholders; I understand that. But I figured I needed to do what’s right for the country and for the national critical infrastructure.

Michael Lynn, at Black Hat 2005, on why he quit his job at Internet Security Systems to disclose the Cisco IOS flaw after Cisco had the pages ripped out of the conference booklet — as reproduced in Bruce Schneier’s account, July 29, 2005

THE FIGHT
Full disclosure vs. the gag order — whether a vendor's legal department can use copyright, trade-secret, the DMCA, or defamation law to stop a researcher from describing a flaw in public FACT
THE WEAPONS
Temporary restraining orders, cease-and-desist letters, DMCA §1201 charges, trade-secret and copyright claims, defamation suits — and, at least once, staff physically tearing printed pages out of binders
THE FRONTS
Craig Neidorf / E911 (1990) · Sklyarov / ElcomSoft (2001) · Blackboard (2003) · Ciscogate / Michael Lynn (2005) · MBTA v. Anderson (2008) · MedSec & Muddy Waters vs. St. Jude (2016)
THE RECORD
Charges dropped, an acquittal, TROs lifted, settlements, and one FBI inquiry that produced no warrant. The gag usually holds for a weekend; the flaw stays real FACT
STATUS
ONGOING — the venue changes (phreak zine, DEF CON, Black Hat, an SEC filing) but the move is the same: lawyers deciding what security research may be spoken aloud

This file is a theme, not a person — a timeline of the landmark cases where a company's legal department tried to be the referee of the disclosure debate. The through-line is a single reflex: when a researcher is about to say something true and inconvenient about a product, the fastest answer is not an engineering fix but an injunction. The counter-reflex is just as real, and the file gives both sides at full strength: some of these researchers signed NDAs and broke them, some cracked copy protection, and one team shorted the stock before it spoke. The archive keeps the filings on all of them.

the drama timeline

ACT I — THE FOUNDING CASE (1990)

Before there was a DMCA, there was a phreak-zine editor, a leaked telephone document valued at tens of thousands of dollars, and a manual you could order from the phone company for thirteen bucks.

  1. FEB–JUL 1990

    United States v. Riggs — the E911 document

    Craig Neidorf, a 20-year-old pre-law student who edited the hacker magazine Phrack, is indicted (Feb 1, 1990) for publishing a BellSouth document about the 911 emergency system that prosecutors valued at tens of thousands of dollars. At trial (July 1990) the defense demonstrates the same information could be ordered from BellSouth as a manual for roughly $13, and expert witnesses testify it contained nothing useful for breaking into systems. The government drops all charges after four days. Neidorf is left with legal bills exceeding $100,000 — the founding template: the flaw (or the document) was never the secret the prosecution claimed.

ACT II — THE DMCA WEAPON (2001–2003)

A new law arrives that makes it a crime to break copy protection — and lawyers discover it doubles as a muzzle. The talk gets you arrested; the C&D gets the talk cancelled.

  1. JUL 16, 2001

    Dmitry Sklyarov, arrested for a slide deck

    Russian programmer Dmitry Sklyarov, employed by ElcomSoft, is arrested by the FBI at the Las Vegas airport the day after presenting at DEF CON — the first criminal prosecution under the DMCA's anti-circumvention provisions. His employer's Advanced eBook Processor undid Adobe's e-book copy protection. Adobe withdrew its complaint; the government pressed on anyway. Sklyarov is held, then released on $50,000 bail, and allowed home to Russia (Dec 2001). In December 2002 a federal jury acquits ElcomSoft on all four counts. The lesson landed: describing how a protection scheme fails could now be a federal crime.

  2. APR 2003

    Blackboard pulls the campus-card talk

    Days before the Interz0ne conference in Atlanta, education-software vendor Blackboard Inc. obtains a restraining order and its law firm sends conference organizers a cease-and-desist, stopping students Billy Hoffman (Georgia Tech) and Virgil Griffith (Alabama) from presenting on security weaknesses in the Blackboard Transaction System — the campus ID / debit-card platform used across U.S. universities. The lawyers invoked the DMCA plus a stack of other statutes. The talk was called off. The vulnerabilities were not.

ACT III — THE PAGES TORN FROM THE BOOK (2005)

The image that defines the whole war: conference staff, the night before, physically ripping thirty pages out of every attendee's binder because a router company's lawyers said so. This is the centerpiece.

  1. JUL 26, 2005

    The binders are gutted overnight

    On the eve of Black Hat, attendees find that roughly thirty pages have been physically torn out of the printed conference proceedings and the presentation CD-ROM withheld — at Cisco Systems' request. The excised pages were Michael Lynn's talk on a remote-code-execution class of flaw in Cisco IOS, the operating system running much of the internet's routers. The tearing-out is the thesis of this entire file in one gesture: not a patch, not a fix — a legal department deciding, page by page, what you are permitted to read.

  2. JUL 27, 2005

    Lynn resigns mid-morning, then gives the talk

    Employer ISS (IBM Internet Security Systems) had forbidden the talk; Lynn opens on a decoy topic, then reverses. He resigns from ISS that morning rather than keep the flaw private, and walks the room through it — comparing IOS to "the Windows XP of the internet." His stated reason, in his own words: ISS "had to do what's right for their shareholders," but he "needed to do what's right for the country and for the national critical infrastructure." The flaw was real; the disclosure was the crime the lawyers were building.

  3. JUL 2005

    The restraining order, the settlement, the FBI

    Within hours, process servers hand Lynn a lawsuit and Cisco and ISS win a restraining order in the Northern District of California — ISS claiming copyright over the presentation, Cisco claiming copyright over decompiled router code and trade-secret protection. Lynn settles: he hands over forensic images of his research and is permanently barred from discussing the vulnerability. FBI agents arrive at the conference; his attorney Jennifer Granick asserts his Fifth and Sixth Amendment rights. No arrest warrant issues. The talk had already happened. That is the part no injunction could tear out.

ACT IV — GAG ORDERS AND SHORT SELLERS (2008–2016)

The muzzle keeps evolving: a transit authority racing to a federal judge overnight, then a medical-device giant suing a startup for defamation over a flaw the government would later confirm.

  1. AUG 2008

    MBTA v. Anderson — three students, one weekend gag

    The Massachusetts Bay Transportation Authority sues three MIT students — Zack Anderson, RJ Ryan, and Alessandro Chiesa — and gets a federal temporary restraining order (Aug 9, 2008) blocking their DEF CON talk on flaws in the CharlieCard fare system. The EFF calls the gag an unconstitutional prior restraint on protected speech. On Aug 19 the court declines to extend the order and it expires; the case later settles. The slides had already been distributed on the conference CD — a textbook Streisand effect. The vendor got a weekend of silence and a permanent headline.

  2. 2010–2014

    weev, Goatse Security & the public-URL question

    The gadfly crew Goatse Security — including weev and Daniel Spitler — found that a public AT&T web address, fed a valid device ID, returned an iPad owner's email, and enumerated it to harvest ~114,000 addresses, which they handed to Gawker. weev was convicted under the CFAA (41 months); the Third Circuit vacated it in 2014 (on venue). The case put the era's sharpest disclosure question in a courtroom: is reading a page a company published to the open web, with no password gate, "unauthorized access" — or the company's own flaw? The scene's answer and the government's never met.

  3. SEP 7, 2016

    St. Jude sues MedSec and Muddy Waters — the lawyer-driven twist

    A new wrinkle: security firm MedSec found alleged vulnerabilities in St. Jude Medical's pacemakers and defibrillators and, instead of disclosing to the vendor, partnered with short-seller Muddy Waters — the two profiting as the stock dropped on their public report. St. Jude fired back with a defamation lawsuit (filed in Minnesota, Sept 7, 2016) alleging false statements, conspiracy, and market manipulation, and denounced the pair for "trying to frighten patients." The device maker's side was serious and legitimate. But the FDA and DHS later confirmed the vulnerabilities were real — the disclosure debate now fought with defamation counsel and an SEC filing instead of a conference binder.

  4. COUNTER-CURRENT

    The opposite pole — when disclosure itself was the racket

    Not every objection to full disclosure came from a legal department. The anti-full-disclosure movement in the scene argued the opposite case entirely: that dumping working exploits in public was itself a racket — free zero-days for criminals, dressed up as principle. Same fight, opposite pole. The lawyers wanted silence to protect the product; the anti-disclosure hardliners wanted silence to deny attackers the ammunition. Both distrusted the researcher holding the microphone.

both sides, on the record

The companies had real interests: Cisco's IOS internals and ElcomSoft's target were genuine intellectual property; Sklyarov's tool really did crack Adobe's copy protection; and some of these researchers signed non-disclosure agreements and broke them. A vendor blindsided at a conference has a legitimate claim that a flaw dumped in public with a working exploit endangers every customer who hasn't patched.

Not all disclosure is clean: MedSec did not report to St. Jude first — it partnered with a short seller and profited from the stock's fall, exactly the conflict St. Jude's suit alleged. University of Michigan researchers publicly questioned the "brickable" claim. When money rides on the timing of a disclosure, the vendor's demand for scrutiny is not automatically censorship.

The flaws kept being real: the E911 document was a $13 manual [4]; ElcomSoft was acquitted [5]; Lynn's IOS flaw was serious enough that the FBI came and left with no warrant [1]; the MBTA students' CharlieCard findings held up [7]; St. Jude's vulnerabilities were later confirmed by the FDA and DHS [9]. The suits gagged the messenger, not the bug.

The remedy was speech-suppression, not repair: torn pages, a restraining order, a DMCA arrest, a defamation suit — each answered a true statement about a product with a legal instrument to stop it being said, rather than an engineering fix [3]. Courts repeatedly declined to make the gags stick.

Prior restraint kept losing: the EFF's First Amendment argument carried in MBTA; the TROs expired; the acquittals came. The pattern is a legal department reaching for the muzzle first and the law declining to hand it over [8].

YOU DECIDE

Some of these researchers broke agreements, cracked copy protection, or shorted the stock before they spoke — and the vendors' interests in IP and patient safety were real. But strip each case to its spine and the same shape appears: a true statement about a flawed product, met not with a patch but with counsel reaching for an injunction, a DMCA charge, or a defamation suit. The flaw was almost always confirmed. The gag almost always lifted. The pages Cisco tore out of the binder are the whole argument in miniature — you can destroy the paper, but the talk already happened.

The archive does not take a side on the NDA. It keeps the filing, the acquittal, and the FDA confirmation — and notes who reached for the muzzle first.

evidence locker

PRIMARY / REFERENCE

  1. Wikipedia — Ciscogate ATTRIBUTED — the ~30 pages torn from the Black Hat 2005 proceedings at Cisco's request, the withheld CD-ROM, Lynn's resignation and talk, the Cisco/ISS restraining order and settlement barring future discussion, and the FBI inquiry that produced no warrant. en.wikipedia.org/wiki/Ciscogate
  2. InfoWorld — "ISS researcher quits job to detail Cisco flaws" ATTRIBUTED — contemporaneous (July 27, 2005) account: Lynn departs ISS, pages removed from the conference handbook, Cisco and ISS threaten legal action. infoworld.com — Black Hat: ISS researcher quits
  3. Schneier on Security — "Cisco Harasses Security Researcher" ATTRIBUTED — July 29, 2005; reproduces Lynn's own words ("what's right for the country and for the national critical infrastructure") and the sequence of the talk and lawsuit. schneier.com/blog/archives/2005/07/cisco_harasses.html
  4. Wikipedia — United States v. Riggs ATTRIBUTED — Craig Neidorf / Phrack / the E911 document; the Feb 1990 indictment, the $13-manual defense, charges dropped after four days, $100k+ in legal costs. en.wikipedia.org/wiki/United_States_v._Riggs
  5. Wikipedia — United States v. Elcom Ltd. ATTRIBUTED — Dmitry Sklyarov's July 16, 2001 DMCA arrest after DEF CON, Adobe's withdrawn complaint, the $50k bail, and the December 2002 acquittal on all four counts. en.wikipedia.org/wiki/United_States_v._Elcom_Ltd.
  6. The Register — "DMCA threats gag security researchers" ATTRIBUTED — April 15, 2003; Blackboard Inc.'s cease-and-desist and restraining order stopping Hoffman and Griffith from presenting on the Blackboard Transaction System at Interz0ne. theregister.com/2003/04/15/dmca_threats_gag_security_researchers

CONTEXT & CROSS-LINKS

  1. Wikipedia — MBTA v. Anderson ATTRIBUTED — the three MIT students, the Aug 9, 2008 TRO blocking the DEF CON CharlieCard talk, the Aug 19 refusal to extend it, and the settlement. en.wikipedia.org/wiki/MBTA_v._Anderson
  2. EFF — MBTA v. Anderson ATTRIBUTED — the Electronic Frontier Foundation's account and First Amendment / prior-restraint argument against the gag order. eff.org/cases/mbta-v-anderson
  3. The Register — "St Jude sues over hacking claim" ATTRIBUTED — Sept 7, 2016; St. Jude Medical's defamation suit against MedSec and Muddy Waters, the short-selling arrangement, and the company's denial. theregister.com/2016/09/07/st_jude_sues_over_hacking_claim
  4. troll.fan — DEF CON / Knight Lightning / The Anti-Security Movement CROSS-LINK — the venue behind Sklyarov and the MBTA gag; the founding E911 case; and the opposite pole of the disclosure fight. troll.fan/dossiers/defcon.html
The standard. Every case here is public court record — indictments, TROs, settlements, an acquittal, and a defamation suit — and each is sourced to the filing or contemporaneous coverage above. The companies' interests are given at full strength: real IP, real patient-safety stakes, and researchers who in some cases broke NDAs or partnered with short sellers. The exculpatory center — that the flaws were repeatedly confirmed real and the gags repeatedly lifted — is likewise sourced. Characterizations are attributed to their authors; no motive is asserted beyond the record. If a line here couldn't survive scrutiny, it wouldn't be on the page.