|
|
|
|
|
by grayhatter
649 days ago
|
|
> The security team is composed of unpaid volunteers who work on numerous time-sensitive projects simultaneously. If the nix volunteers aren't held to reasonable security defect reporting standards, why do you hold the vulnerability reporter to higher standards? I'd say, if the rule is volunteers are able to YOLO with other users' security so can the reporters right? |
|