> My actions are in accordance with responsible disclosure guidelines (Google Project Zero discloses vulnerabilities in 90 days after reporting them to vendor, ZDI - in 120). I have waited much longer, up to half a year in one case.
"Responsible" disclosure guidelines only benefit corporations. They do not protect consumers. Why should independent researchers - working for free, no less (and sorry, the well-below-minimum-wage pittance that is most bounties does not count as not working for free) have to cow tail to corporate guidelines?
If you find a vulnerability, do everyone a favor and disclose it immediately. This places pressure on the corporation to fix it immediately, instead of ignoring it indefinitely.
Also, it's "This makes it immediately available to exploit before a fix can even _theoretically_ be developed", not "This places pressure on the corporation to fix it immediately".
"Responsible" disclosure guidelines only benefit corporations. They do not protect consumers. Why should independent researchers - working for free, no less (and sorry, the well-below-minimum-wage pittance that is most bounties does not count as not working for free) have to cow tail to corporate guidelines?
If you find a vulnerability, do everyone a favor and disclose it immediately. This places pressure on the corporation to fix it immediately, instead of ignoring it indefinitely.