Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> My actions are in accordance with responsible disclosure guidelines (Google Project Zero discloses vulnerabilities in 90 days after reporting them to vendor, ZDI - in 120). I have waited much longer, up to half a year in one case.

"Responsible" disclosure guidelines only benefit corporations. They do not protect consumers. Why should independent researchers - working for free, no less (and sorry, the well-below-minimum-wage pittance that is most bounties does not count as not working for free) have to cow tail to corporate guidelines?

If you find a vulnerability, do everyone a favor and disclose it immediately. This places pressure on the corporation to fix it immediately, instead of ignoring it indefinitely.



FYI, it's "kowtow", not "cow tail".

Also, it's "This makes it immediately available to exploit before a fix can even _theoretically_ be developed", not "This places pressure on the corporation to fix it immediately".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: