top | item 44585048

(no title)

winstonhowes | 7 months ago

100%. We want to ensure we can fix real security issues responsibly before details are published. In practice, if a researcher asks to disclose after we've addressed the issue, we're happy for them to publish.

discuss

order

DANmode|7 months ago

In practice, it sounds like you guys didn't accept this dude's valid vuln because he didn't register and sign his life away.

tptacek|7 months ago

They just stated it was all just model hallucination, and was not in fact a valid vuln.