Hacker News new | ask | show | jobs
by tptacek 2801 days ago
I won't do work for the Federal government, but I've worked with companies of all sizes in healthcare, manufacturing, finance, and utilities, and at none of them was it a norm that internal vulnerabilities be disclosed publicly.

People keep saying that there are certain kinds of companies where you have to disclose, and I have come to the conclusion that they are simply making that up because it sounds good to them.