|
|
|
|
|
by janalsncm
214 days ago
|
|
I guess the question that a person at Google who discovers a bug they don’t personally have time to fix is, should they report the bug at all? They don’t necessarily know if someone else will be able to pick it up. So the current “always report” rule makes sense since you don’t have to figure out if someone can fix it. The same question applies if they have time to fix it in six months, since that presumably still gives attackers a large window of time. In this case the bug was so obscure it’s kind of silly. |
|