| ▲ | traceroute66 an hour ago | |||||||||||||||||||||||||
The majority of your security bulletins are as the result of third-party reports to you. Which, by definition, means they are not done by you, which means you don't know when they will be done or how much of your code base they are looking at. I think you know full well what I mean by a security audit. If you don't, go look at, for example, the ones that Mullvad publish for their software https://mullvad.net/en/blog/tag/audits. Please do not try to portray SOC2 as being the same thing as a code audit. And IF you have regular code audits, then please publish suitably redacted reports in public on your website. Just like everyone else does ! | ||||||||||||||||||||||||||
| ▲ | apenwarr 40 minutes ago | parent [-] | |||||||||||||||||||||||||
(Tailscale CEO) I don't know what to tell you. The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing. They don't need bulletins. Bugs that are found by other people are found, by definition, after release. They are therefore more likely to need a bulletin. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||