Using the scientific method in security research
Security research often starts with behavior that does not match the expected design. The signal may be a crash, a timing difference, a malformed response, an unexpected privilege boundary, or a log entry that appears only under a specific condition. The first mistake is to treat that signal as the conclusion. A crash is an observation. A vulnerability claim requires a working explanation of the path that caused it, the condition that triggers it, and the impact that follows from it....