Hacker News new | ask | show | jobs
by zamnos 1156 days ago
I recommend waiting the industry standard 90 days before volunteering intended behavior.
2 comments

Why wait? The point of the 90 days is to give them time to fix it, but if they consider it intended behavior, they aren't going to fix it.
If they don't intend to fix it, then what's the problem with waiting? The bug's still gonna be there in 90 (minus however long it's already been) days and rushing disclosure really doesn't reflect well on you as a researcher to the rest of the industry. Ofc if you have your own bug, you're welcome to disclose it whenever you want, even violating NDAs if you feel like the vendor hasn't gone far enough. There may be legal repercussions with that last bit, but again, that's up to you.
Oh that’s cool! I forgot about this!