Remix.run Logo
akerl_ 2 days ago

The original objection was about branding: the term "responsible disclosure" was specifically coined by entities that wanted to frame involving the vendor prior to disclosure as good, and disclosing immediately to the public as bad. We shouldn't use it, because that framing is incorrct.

"Coordinated disclosure" doesn't have any of that. It means "You gave the developer information in advance so that they could prepare/remediate/etc". Which is what it means to coordinate. If I call you up and say "Hey Dylan, I'm going to be at the bar in an hour if you want to grab drinks", I'm coordinating. If I just turn up at the bar and start drinking without contacting you, I am not coordinating.

We don't need to invent another bag of terms for the varying ways that you can respond to my message, because the primary party that matters when we're talking about disclosure methodology is the person releasing the disclosure.

Dylan16807 a day ago | parent [-]

It's not a friendly invite that could turn into doing a thing together. "I'm going to do something you probably don't like in this many days, by myself." is not coordinating. It's too one-sided.

Replace going to the bar with telling me you're going to the grocery store, with no expectation that if I show up you'll talk to me.