logoalt Hacker News

jacobgkauyesterday at 8:38 PM2 repliesview on HN

They're asking the nature of the third party's discovery/publishing. Someone on the inside who decided to leak it anonymously? Someone else who was able to access some private communication they shouldn't have been able to see? Or a third party who happened to discover the same vulnerability (which seems less unlikely than normal since this is so similar to Copy Fail), but didn't follow disclosure procedures?


Replies

staticassertionyesterday at 8:40 PM

The commit for the fix was public. Someone noticed. An exploit was published.

show 1 reply
lofaszvanittyesterday at 9:13 PM

Following disclosure procedures? The main cause that kills the need to take security seriously.