|
|
|
|
|
by metadat
598 days ago
|
|
Warning shots across the bow in private are the polite and responsible way, but malicious actors don't typically extend such courtesies to their victims. As such, compared to the alternative (bad actors having even more time to leverage and amplify the information asymmetry), a timely public disclosure is preferable, even with some unfortunate and unavoidable fallout. Typically security researchers are reasonable and want to do the right thing with regard to responsible disclosure. On average, the "bigger party" inherently has more resources to respond compared to the reporter. This remains true even in open source software. |
|