logoalt Hacker News

john_strinlaitoday at 12:24 AM1 replyview on HN

you must be unfamiliar what used to happen before hard deadlines were set on disclosure. it was much worse for the users.

here is a good start: https://projectzero.google/vulnerability-disclosure-faq.html...

there is ~3 decades of more context if you search for it.


Replies

stingraycharlestoday at 8:05 AM

tldr: if security issues don’t get disclosed (or the real threat of disclosure) they won’t get fixed / prioritized.