Choi, J., Fershtman, C. and Gandal, N. (2010). Network security: vulnerabilities and disclosure policy Journal of Industrial Economics, 58(4):868--894.
-
Affiliated authorChaim Fershtman
-
Publication year2010
-
JournalJournal of Industrial Economics
Software security is a major concern for vendors, consumers and regulators. When vulnerabilities are discovered after the software has been sold to consumers, the firms face a dilemma. A policy of disclosing vulnerabilities and issuing updates protects only consumers who install updates, while the disclosure itself facilitates reverse engineering of the vulnerability by hackers. The paper considers a firm that sells software which is subject to potential security breaches and derives the conditions under which a firm would disclose vulnerabilities. It examines the effect of a regulatory policy that requires mandatory disclosure of vulnerabilities and a {\textquoteleft}bug bounty{\textquoteright} program.