▲ | Dylan16807 2 days ago | |
Reporting the bug to the vendor is coordinating in a weak sense, but you're not coordinating the disclosure unless they have input in how the disclosure happens. If an email asking them to fix it qualifies as coordinated disclosure, then an immediate public post about the bug is also coordinated disclosure. It also brings them in and asks them to take actions. | ||
▲ | tptacek 2 days ago | parent [-] | |
Even "responsible disclosure" didn't necessarily give vendors input into "how" the disclosure happened, only "when". |