Hacker News new | past | comments | ask | show | jobs | submit login

Full disclosure is reasonable, and the only truly effective methodology. Anything else just allows vendors to delay or ignore.



It takes time to understand a vulnerability, create a patch and distribute it.

Please stop confusing slowness with an intent to delay or ignore.


Vuln disclosure has historically been associated with vendors delaying and ignoring issues for a long long time. That's the whole reason FD came about. There's no confusion on my part.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: