Hacker News new | ask | show | jobs
by debugnik 123 days ago
> You cannot disclose this to public. Even with good intentions.

Bullshit, NIS 2 article 12 specifically says CSIRTs must coordinate the negotiation of a disclosure timeline between reporter and provider. I'd say offering a 30 day embargo while CC'ing the relevant CSIRT is the start of such negotiation from the reporter.

My biggest doubt about this story, LLM writing aside, is the lack of mention of a CSIRT follow up.