| ▲ | michaelt 2 hours ago | |
> So no responsible disclosure, I see. If I, a corporation, declare that I only accept security reports carved on clay tablets in ancient greek and hand-delivered to my office in Timbuktu during a total solar eclipse - does that stop responsible security researchers from disclosing their findings publicly? Of course not. If the guy sends a clear message to the best public contact address he can find with 15 minutes of searching; and gives them 30 days to patch before publicly disclosing the bug; then he's performed responsible disclosure. The vendor's corporate policies and release cycles and contact addresses and triage procedures are their problem. | ||