|
|
|
|
|
by dotancohen
212 days ago
|
|
Google publicly disclosing the bug doesn't only let affected users know. It also lets attackers know how they can exploit the software. Holding public disclosure over the heads of maintainers if they don't act fast enough is damaging not only to the project, but to end users themselves also. There was no pressing need to publicly disclose this 25 year old bug. |
|