Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

IMHO There should be an in between step, not just 90 day timeout for full disclosure, and saying nothing. Maybe CVE ID and vague description, then extend full disclosure by 7-14 days.


I disagree, 90 days is sufficient time to work offline with the reporting entity. If they cannot come to agreement in 90 days what is another <arbitrary amount of time> going to matter? It just further extends what they are already doing, not prioritizing it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: