Remix.run Logo
michaelt 2 hours ago

> So no responsible disclosure, I see.

If I, a corporation, declare that I only accept security reports carved on clay tablets in ancient greek and hand-delivered to my office in Timbuktu during a total solar eclipse - does that stop responsible security researchers from disclosing their findings publicly?

Of course not.

If the guy sends a clear message to the best public contact address he can find with 15 minutes of searching; and gives them 30 days to patch before publicly disclosing the bug; then he's performed responsible disclosure.

The vendor's corporate policies and release cycles and contact addresses and triage procedures are their problem.