top | item 31925967

(no title)

vixentael | 3 years ago

A valid point. But responsible disclosure in the world of un-patchable devices that actually move and can cause physical harm once pwned feels a little bit different. While we've done things to mitigate a blast radius, publicising guilty names would still lead to lots of damage because you know, these are toy cars.

discuss

order

ziddoap|3 years ago

I am the only one who knows my risk tolerance and threat model. I do not appreciate when other researchers think that they know my tolerance and threat model better than I do.

The only reason not to release names after a reasonable responsible disclosure timeframe is because the researchers somehow think they are the only ones that will ever find that flaw. Pure hubris. Some malicious person will eventually find those same flaws, and then I'm fucked without being given the opportunity to evaluate whether or not I want to risk getting fucked.