(no title)
dbl000 | 3 months ago
If you announce a vulnerability (unspecified) is found in a project before the patch is released doesn't that just incentivize bad actors to now direct their efforts at finding a vulnerability in that project?
dbl000 | 3 months ago
If you announce a vulnerability (unspecified) is found in a project before the patch is released doesn't that just incentivize bad actors to now direct their efforts at finding a vulnerability in that project?
saagarjha|3 months ago
Bratmon|3 months ago
Changing the norm to "We don't announce unpatched vulnerabilities but there is a deadline" was a massive improvement.
inkysigma|3 months ago
I don't see why actors would suddenly reallocate large amounts of effort especially since a patch is now known to be coming for the issue that was found and thus the usefulness of the bug (even if found) is rather limited.