|
|
|
|
|
by eyalitki
318 days ago
|
|
Not sure what is the measurable metric here, and what will be considered a success in this trial period. Propagating the fix downstream depends on the release cycles of all downward vendors. Giving them a heads up will help planning, but I doubt it will significantly impact the patching timeline. It is highly more likely that companies will get stressed that the public knows they have a vulnerability, while they are still working to fix it. The pressure from these companies will probably shut this policy change down. Also, will this policy apply also to Google's own products? |
|
Google's products represent 3/6 of the initial vulnerabilities following this new reporting policy in the linked reporting page.