A cybersecurity firm, “Red Access,” contacted us less than 24 hours before going to the media with v...
TL;DR · AI 摘要
Replit CEO Amjad Masad publicly rebukes cybersecurity firm Red Access for attempting 24-hour media disclosure of vague security claims, affirming Replit’s adherence to responsible disclosure norms and recent security product launches.
核心要点
- Red Access attempted irresponsible 24-hour disclosure instead of standard private coordination.
- Replit clarifies that public app visibility is intentional and user-controlled, not a vulnerability.
- Replit launched Security Agent and Auto-Protect to proactively strengthen platform security.
结构提纲
按章节快速跳转。
- §事件起因
Red Access在24小时内向媒体曝光Replit相关安全主张,未遵循标准披露流程。
引用CISA、CERT/CC等机构标准:需私密通报+合理修复窗口期。
公开应用可访问属设计行为,非漏洞;隐私设置一键可控。
上线Security Agent与Auto-Protect两款新安全产品。
重申欢迎遵守规范的安全研究人员,并愿配合整改。
思维导图
用一张图看清主题之间的关系。
查看大纲文本(无障碍 / 无 JS 友好)
- Replit回应Red Access安全争议
- 披露失范
- 24小时媒体通牒
- 缺乏技术细节
- 平台事实澄清
- 公有应用=预期行为
- 隐私设置一键切换
- 主动安全建设
- Security Agent
- Auto-Protect
金句 / Highlights
值得收藏与分享的关键句。
A 24-hour countdown to a press cycle is not [responsible disclosure].
Public apps being accessible on the internet is expected behavior.
Just in the past week, we launched two security products: Security Agent and Auto-Protect.
We welcome responsible security research and have a long history of working constructively with researchers who follow standard disclosure practices.
This is not how responsible security research works. The standard practice in terms of disclosure policies, as followed by CISA, CERT/CC, and most major" / X
A cybersecurity firm, “Red Access,” contacted us less than 24 hours before going to the media with vague claims about Replit. This is not how responsible security research works. The standard practice in terms of disclosure policies, as followed by CISA, CERT/CC, and most major firms, is to share findings privately and allow a defined window for remediation before public disclosure. A 24-hour countdown to a press cycle is not that. From the limited information they shared, their core claim appears to be that some users have published apps on the open web that should’ve been private. Replit allows users to choose whether apps are public or private. Public apps being accessible on the internet is expected behavior. Privacy settings can be changed at any time with a single click. Vibe Coding is a rapidly developing space, and we take our responsibility to both provide tools to create secure apps and educate our customers very seriously. Just in the past week, we launched two security products: Security Agent and Auto-Protect. If Red Access shares a list of impacted users, we will proactively default those apps to private and notify users directly. We welcome responsible security research and have a long history of working constructively with researchers who follow standard disclosure practices. That offer remains open.