> ## Content Index
> Fetch the complete content index at: https://blog.disclose.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# 2020: A Good Year for Hackers
- URL: https://blog.disclose.io/2020-a-good-year-for-hackers/
- Published: 2020-12-31T13:01:00.000Z
- Updated: 2026-02-09T02:37:47.000Z
- Description: A look back at 2020's major wins for the security research community — from CFAA reform progress to expanded safe harbor provisions. How the year shaped the future of ethical hacking and vulnerability disclosure.
- Author: Disclose.io
- Tags: Community

### 2020 Highlights

In spite of a lot going on around us, 2020 was a very good year for hackers, and there is much to celebrate as we charge up for 2021.

![](https://storage.ghost.io/c/b2/99/b299a9ed-e13d-42f9-b97d-94a1f8649d42/content/images/2026/02/456efa25-e736-4823-b427-d129dd95806a_2124x1593-jpeg.jpg)

I wanted to post a quick, and by no means incomplete, recap of some of the amazing stuff [disclose.io](http://disclose.io/?ref=blog.disclose.io) members and contributors saw happen in the interest of the health of the Internet’s Immune System:

- The [DHS/CISA BOD 20-01](https://cyber.dhs.gov/bod/20-01/?ref=blog.disclose.io) mandate for vulnerability disclosure was finalized and actioned.
- We [responded](https://disclose.io/voatz-response-letter/?ref=blog.disclose.io) to the Voatz amici briefing in the Van Buren case, which was [subsequently cited](https://www.supremecourt.gov/DocketPDF/19/19-783/155055/20200928114834562%5F19-783ReplyBriefForPetitioner.pdf?ref=blog.disclose.io) in the case documents despite coming in after the Amici Briefing cut-off… Judging by the hearings, the SCOTUS judges read and paid attention to it too.
- Election Systems manufacturers including [ES&S](https://www.essvote.com/storage/2020/08/ESS%5Fvulnerability%5Fdisclosure%5Fpolicy.pdf?ref=blog.disclose.io), [Dominion](https://www.dominionvoting.com/coordinated-vulnerability-disclosure-policy/?ref=blog.disclose.io), and [Hart](https://www.hartintercivic.com/wp-content/uploads/HartVulnerabilityDisclosurePolicy%5F82020.pdf?ref=blog.disclose.io) all launched VDPs with safe harbor provisions based on the [disclose.io](http://disclose.io/?ref=blog.disclose.io) core terms.
- We [signed on to a letter](https://www.eff.org/deeplinks/2020/11/elections-are-partisan-affairs-election-security-isnt?ref=blog.disclose.io) alongside EFF, the CDT, and others protesting the politicization of Election Security ahead of the termination of Chris Krebs.
- [@cyberlawclinic](https://twitter.com/cyberlawclinic?ref=blog.disclose.io) published “[A Researcher’s Guide to Some \[US\] Legal Risks of Security Research](https://m.disclose.io/3mExumo?ref=blog.disclose.io)” by [@KendraSerra](https://twitter.com/KendraSerra?ref=blog.disclose.io) and others, with a shoutout to [@disclose\_io](https://twitter.com/disclose%5Fio?ref=blog.disclose.io), [#diodb](https://twitter.com/hashtag/diodb?ref=blog.disclose.io), and the need for clear VDP language from Vendors.
- The [IoT Cybersecurity Improvement Act of 2020](https://www.congress.gov/bill/116th-congress/house-bill/1668?ref=blog.disclose.io) was signed into law, including requirements for VDP.
- The [NIST 800-53 R3](https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final?ref=blog.disclose.io) standard came out with a core recommendation for VDP and an excellent explanation of “why it’s not really an option if you think about it”.
- Amazon Web Services (AWS) [adopted the core terms](https://twitter.com/z1g1/status/1324797190204755969?ref=blog.disclose.io) with full safe harbor, representing a sizeable percentage of the Internet.
- CISA released it’s [GUIDE TO VULNERABILITY REPORTING FOR AMERICA’S ELECTION ADMINISTRATORS](https://www.cisa.gov/sites/default/files/publications/guide-vulnerability-reporting-americas-election-admins%5F508.pdf?ref=blog.disclose.io), referencing the disclose.io [dioterms](https://github.com/disclose/dioterms?ref=blog.disclose.io) repository.
- The States of [Iowa](https://sos.iowa.gov/pdf/IOWA%5FSOS%5FVDP%5FPolicy.pdf?ref=blog.disclose.io) and [Ohio](https://www.ohiosos.gov/vulnerability-disclosure-policy/?ref=blog.disclose.io) both launched VDPs, also with full authorization provisions.
- We saw more organization deploy the [disclose.io](http://disclose.io/?ref=blog.disclose.io) seal as a signal to hackers, their customers, and their industry peers that they are taking proactive steps to listen to the Internet’s security feedback.
- The [diodb](https://github.com/disclose/diodb?ref=blog.disclose.io) list broke 2,000 entries and is now pushing towards 3,000!  
### Get involved!  
This simplest way to get engaged with The [disclose.io](http://disclose.io/?ref=blog.disclose.io) Project is:

  - Sign Up for our [community](https://community.disclose.io/?ref=blog.disclose.io),
  - [Introduce yourself](https://community.disclose.io/t/getting-started-meet-your-fellow-disclose-io-community/30/15?ref=blog.disclose.io), and
  - Watch [this space](https://community.disclose.io/c/general/5?ref=blog.disclose.io) for ways to get involved in 2021! Thank you for your support!  
I hope each of you have an amazing and restful holiday season, however you’re planning to celebrate this year, and that there are opportunities to connect, reflect, and refresh ahead of what is shaping up to be an important and impactful 2021!