▲ | tptacek 2 days ago | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
There is no basic idea of "responsible disclosure". The term was literally coined so that vendors could call researchers "irresponsible" when they didn't do what the vendors asked. Sometimes immediate disclosure is warranted! | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
▲ | Dylan16807 2 days ago | parent [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I get it, you don't like that term. But the idea of releasing after a fixed delay is fine. That idea should have a name. We shouldn't imply that releasing after a delay and giving the vendor power over it are the same thing. They should not be lumped together under "coordinated disclosure". | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|