| ▲ | ori_b 2 hours ago | ||||||||||||||||
Mind explaining how sitting on it a month after the patch landed is 'faster'? To my mind, that's a month where attackers could analyze commit logs, but maintainers are not acting with urgency to ship fixes. | |||||||||||||||||
| ▲ | tptacek 2 hours ago | parent [-] | ||||||||||||||||
No, I wouldn't, because my own preferences are towards immediate disclosure. Tavis Ormandy dropped Zenbleed out of the sky onto us. It wasn't comfortable, it was a scramble for us, but I don't blame Tavis for it; he made a principled call. Better that people know, than that information be concealed from them while designated elites perform a process. | |||||||||||||||||
| |||||||||||||||||