Hacker News new | ask | show | jobs
by sirdarckcat 1810 days ago
Might be worth noting, 90 days are how long Google thinks it is reasonable to keep vulnerabilities secret without a fix.

The longer it is kept secret, the benefits of the public knowing about it outweigh the risks.

Not all vulnerabilities can be fixed in 90 days, but they can be disclosed.