4 ms·
Great write up. But does this mean that Google doesn't hold themselves to project zero's 90 days before disclosure? (Or have they realized that 90 days reall
by quicklyfrozen 11y ago
Great write up. But does this mean that Google doesn't hold themselves to project zero's 90 days before disclosure?
(Or have they realized that 90 days really isn't enough time?)
- laginimaineb 11y agoIn this case, it seems so. However, I must say I've reported many vulnerabilities to Google since and they've all been handled within that time-frame.
- cyphar 11y agoIs there a reason you didn't publicly disclose after 90 days? (I'd argue that the criticality of the vulnerability would justify a 7-day timeframe). The one problem with the way the security community deals with large vulnerabilities is that the researchers don't stick to their guns regarding responsible disclosure. I would prefer to know that I have to do <XYZ> to minimise the impact rather than find out that I was vulnerable for more than 5 months. Hell, I'd be happy to stop using my smartphone for a week if it meant the problem would be solved faster.