4 ms·
90 days + 14 days grace time. Why isn't that enough?
by TwoNineA 9y ago
90 days + 14 days grace time.
Why isn't that enough?
- jsgo 9y agodepends how embedded the issue is. If the fix for it is going to break or expose other things, it could be that more time is needed. I don't mind that 90 days is a soft deadline, at which point as long as they're showing determinable progress on the issue, all is well until it is patched. But disclosing the bug before a fix is in place exposes users to possible actors that wouldn't know of said issue previously (ie like WannaCry being based on leaked NSA offensive tools. Leaking effectively being an involuntary disclosure).
- ocdtrekkie 9y agoIt took Google five months to get KRACK patched on the Pixel 2, despite third party ROM authors doing it in two days. Suffice to say, many vendors miss deadlines for this stuff on occasion. There are probably a number of reasons for this, including difficulty of repair, the fact that third party software may depend on the broken functionality, etc. Microsoft and Google both patch security updates every single month that fall well within the common 90 day disclosure window. And then every so often, they fail to.