|
|
|
|
|
by pvg
2304 days ago
|
|
In what way did they violate their own rules? Google didn't prevent the researcher from disclosing and the researcher could have disclosed - the timeline describes requests, not demands. For reference, Project Zero's disclosure FAQ: https://googleprojectzero.blogspot.com/p/vulnerability-discl... There are several cases in which deadlines were extended way beyond 90 days. And in the post itself, the researcher points out they could (and, in hindsight, feel they should) have imposed a hard 90 day deadline. |
|