That's still extremely different to this in one of the GP comments:
> There is no such thing as "the responsible disclosure protocol".
And yes, I admit I got dragged down to their level and beat myself with a dumb stick in the process.
There is no such thing as "the responsible disclosure protocol".
There isn’t such a thing. Coordinated disclosure (sometimes called responsible disclosure by people who want to inject their morals into one available option so as to paint the others as irresponsible) exists. As has been noted, some large groups like Project Zero use 90/+30, but that isn’t a set protocol; it’s a thing some folks picked and others have copied. If a research group announced tomorrow that they were doing a flat 42 days from notification to release, they would still be doing coordinated disclosure.