|
|
|
|
|
by woodruffw
323 days ago
|
|
This policy change makes sense to me; I'm also sympathetic to the P0 team's struggle in getting vendors to take patching seriously. At the same time, I think publicly sharing that some vulnerability was discovered can be valuable information to attackers, particularly in the context of disclosure on open source projects: it's been my experience that maintaining a completely hermetic embargo on an OSS component is extremely difficult, both because of the number of people involved and because fixing the vulnerability sometimes requires advance changes to other public components. I'm not sure there's a great solution to this. |
|
For customers, it also gives them leverage to contact vendors and ask politely for news on the patch.