|
|
|
|
|
by capt8bit
3996 days ago
|
|
You are absolutely right. Big difference. I did not mean to imply that it was 5 days, regardless of holidays/weekends. In fact, because we are online more often during holidays, it is during holidays that we most often find vulnerabilities that we need to disclose. Especially during December, we are much more lenient. |
|
My comment was supposed to be an addendum but I failed by nitpicking and questioning your interpretation. I'm sorry.
As a security researcher, may I ask you these questions:
Which channel are you using as a first contact ? Would it be enough for me as a saas supplier to monitor security@myservice.com ? I must admit I'm bit afraid by a cleartext channel for this kind of disclosure. Would you have some recommandations for the receiving part of the vulnerability ?