Remix.run Logo
grncdr 4 hours ago

I think the idea is that dedicated security firms and/or automated scanners will discover exploits in the cooldown period.

woodruffw 2 hours ago | parent | next [-]

Yep, this is the thesis behind them. I wish people engaged more fully with this argument: it’s possible to believe that security vendors won’t do a good job of upholding their side of the bargain, but I’ve yet to see anybody argue that rather than making a faulty universalization argument against cooldowns.

weinzierl 36 minutes ago | parent | prev [-]

If this is the idea, why don't we let the dedicated security firms and/or automated scanners find the vulnerabilities before the release?

You need an early release in the "given enough eyeballs all bugs are shallow" world because you need the eyeballs, but if you count on specialists and scanners no general availability release is necessary and hence no cool down.

john_strinlai 22 minutes ago | parent [-]

i am not sure what the benefits of your proposal are compared to the "cooldown period" way.

the releases will be delayed for the same time period, but you increase the amount of coordination required significantly.