|
|
|
|
|
by bzbarsky
2510 days ago
|
|
For what it's worth, Mozilla routinely discloses internal findings, subject to the same policy as external findings: the bug report is opened up once the fix has shipped to a sufficient fraction of users. So it's not "literally no company". ;) Disclosure: I work for Mozilla and I have reported a number of security bugs on our code, the vast majority of which are now public. |
|
Regardless: that's a good point. I should have said, public disclosure of internal findings is not an industry norm. Mozilla is a good counterexample to the argument that everyone close-holds internal findings.