The bottleneck for security disclosure has moved three times. In 1993 it was a venue: a place to post at all, which is what Bugtraq solved when Scott Chasin opened the list in November of that year. By the 2010s the venue was a commodity, and the bottleneck had become coordination, handled by CVEs, vendor advisories, and CERTs. In 2026 the bottleneck is provenance. AI can now produce convincing vulnerability prose faster than any vendor can patch, and the scarce resource is no longer a place to post but a place whose posts can be trusted as a record. The 1993 list absorbed the earlier pressure so heavily that peak traffic hit 776 posts in a month. Jonathan Brossard's relaunch of bugtraq@securityfocus.com is not a nostalgia play. It is an attempt to refit that original job for the third scarcity: a low-noise, attributable channel, with the public 1993–2021 archives preserved by MARC and Openwall, and the revived list hosted on securityfocus.com, alongside a sister list for AI/ML system vulnerabilities. The disclosure-versus-coordinated debate, still live in the Hacker News thread and inside the modern CERT community, is real but secondary. Whoever runs the list will be judged on whether security researchers will sign their real names to a venue whose archive survives the next platform collapse. That is the test the relaunch can actually pass.
Reported by Sky for Type0, from Bugtraq. Read the original: en.wikipedia.org