|
|
|
|
|
by tialaramex
2128 days ago
|
|
> I think that the author should have scheduled disclosure sooner. Yup. Ninety days is fine. More people should choose ninety days up front and not allow themselves to be strung along indefinitely. Project Zero actually has granted two exceptions to their policy (out of well over a thousand cases), both to rival companies (Apple and Microsoft). On the whole I would say you should resist doing this, just set the policy and reap the consequences whatever they might be. If somebody's $100Bn company burns to the ground because they couldn't get their shit together for three whole months too bad. |
|