4 ms·
Is the security disclosure policy 3 business days? https://www.theverge.com/2013/5/23/4358400/google-engineer-bashes-microsoft-discloses-windows-flaw https://w
by quickben 8y ago
Is the security disclosure policy 3 business days?
https://www.theverge.com/2013/5/23/4358400/google-engineer-bashes-microsoft-discloses-windows-flaw https://www.theverge.com/2013/5/23/4358400/google-engineer-b...
Do you think Google acted in a fair or unfair matter?
- DannyBee 8y agoIt's interesting you have to go back to 2013 to find something. 1. There's actually nothing here to suggest this was done as part of project zero or any part of tavis's job. In fact, this was before project zero even existed, AFAIK. 2. He published details about it in march (O(60) days), as he said. It was still a security bug then, just missing a working exploit. 3. This thread produced a working exploit. I'm gonna go with "either unrelated or fair". Unrelated if it wasn't done by Tavis as part of his job, and fair if it was given the timeline and disclosure policies that existed at the time.
- quickben 8y agoI wasn't going down some reverse chronological timeline. It was in the first page of many of results. About 1,2 and 3, if you would zoom a bit out, you have an advertising company that is, by it's intentional actions, making the rest look bad. Outside of contacting the relevant companies, they don't have to push the exploits to the world, yet they do. The rest is just how one spins the story depending on the size of the paycheck received from Google. There is nothing left to conclude, I am out of this thread.