Hacker Newsnew | past | comments | ask | show | jobs | submit | cyberbase's commentslogin

Notices, pressure or teeth, should be effective and reduce harm... 1. Notify Manufacture w Details, Start 90 Day Clock. 2. 90 Days, Notify public of discovery and notice date, NO public details. Notify Reputable Security Vendors of details to prep defense of un-patched bug. 3. 180 days release limited details publicly and date of notices to MFG and Sec Vendors. THIS will build public pressure on whole ecosystem and limit impact.


At step 2: any release of any information is enough to get people looking in the right general direction.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: