Last February, a security researcher claimed he had the ability upload non-media files to YouTube, and he reported this as a major vulnerability hoping that Google would pay him for the discovery. Google, in response, said the discovery was simply a non-security bug.

What exactly is security research anyway?

Listen to episode 130 of our Security Slice podcast and hear Craig Young and Tyler Reguly discuss the difference between finding a bug and finding a vulnerability, and why security research should amount to more than a catchy headline, and why we should consider global governance might be the answer to the gray areas in security research.

