▲ | mananaysiempre 4 days ago | ||||||||||||||||
It depends on the maintainer, some of them have indeed found themselves unwilling to continue their work in part because of Project Zero. > I just stepped down as libxslt maintainer and it's unlikely that this project will ever be maintained again. It's even more unlikely with Google Project Zero, the best white-hat security researchers money can buy, breathing down the necks of volunteers. | |||||||||||||||||
▲ | tptacek 4 days ago | parent [-] | ||||||||||||||||
I know it's hard to believe this given the circumstances --- that maintainer has a very good reason for stepping back, absolutely no shade to give there --- but GPZ is doing a service for these projects. The vulnerabilities they find are there whether or not Google or anybody else steps up on the implementation side. They are simple facts of the software, and it's difficult, expensive, and important to uncover those facts. | |||||||||||||||||
|