Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> some arbitrary number of days you made up

As a separate datapoint, Google's Project Zero has a default 90 day public disclosure period too.

Generally, it's highly likely that the (really) bad guys already know about the exploit. Leaving the exploit known only to them and the vendor doesn't help the most vulnerable (ie, those targeted by the (really) bad guys)

~3 months is also a reasonable amount of time for coding, review, testing, QA, etc. I don't know if the author was up front about the 90 day deadline with Apple, and if not, that's not particularly friendly, but it's not out of line with other major players in the space.



not only that but i've seen security people extend 90 days when the vendor asks.


Based on the information supplied, the vendor didn't ask.

As an Apple user, the only part about this situation that is disappointing is Apple.

Depressingly, there still isn't an overall competitor that can deliver products that meet my requirements as well as Apple can, so I remain stuck.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: