4 ms·
You are assuming that the white hat security researcher was the first to discover the flaw. That is a perfectly reasonable assumption, and your position is perf
by desdiv 8y ago
You are assuming that the white hat security researcher was the first to discover the flaw. That is a perfectly reasonable assumption, and your position is perfectly reasonable given that assumption.
GP was assuming that the white hat security researcher was not the first to discover the flaw, and that the flaw is actively being used to attack users. That is a perfectly reasonable assumption, and GP's position is perfectly reasonable given that assumption.
- MaxBarraclough 8y agoThat's still not enough. Even if bad guys are already using the exploit in the wild, it still isn't responsible to immediately make it public. If the exploit isn't already public, that means the bad guys are treating it as something to be traded in secret. (And of course, the only reason we're discussing this is that the exploit is not already public.) Instantly publishing the details of the exploit may well broaden its use by bad actors, by reducing its market price to zero.