▲ | Dylan16807 2 days ago | |||||||||||||||||||||||||
Let's use neither term in some situations then. It's not just "imprecise" when the term claims exactly one thing and that thing didn't happen. If people start referring to any non-immediate disclosure as "coordinated", that causes the same kind of bad effect you were worried about. People get pressured to coordinate because they think most researchers are always coordinating. I don't want that to happen either. I would never say "irresponsible" just because of timing. You're right that "responsible" is a mess. But "coordinated" if misused also is a mess and also gets coercive. | ||||||||||||||||||||||||||
▲ | akerl_ 2 days ago | parent [-] | |||||||||||||||||||||||||
You've picked a really weird hill to die on here. Coordinated disclosure exists and means what we're describing it to mean: a disclosure where the researcher attempts to reach out to the vendor to remediate prior to publication. That you've latched on to a specific opinion about what "coordination" means that excludes that behavior doesn't change how the term works in the security field, what it means, or whether or not it's preferable to "responsible disclosure" to describe that set of actions. | ||||||||||||||||||||||||||
|