4 ms·
> You don't see how the risk might increase when more people learn about the vulnerability? Do you see the risk of having a vuln that is completely unknown sti
by JakeTheAndroid 7y ago
> You don't see how the risk might increase when more people learn about the vulnerability?
Do you see the risk of having a vuln that is completely unknown still exploitable in your stack?
> What? They provided proof-of-concept exploits just one week after the patch was provided. That's apparently not "immediate" in the eyes of security researchers, but try asking the average user if that's enough time to expect them to update.
Why are critical issues not being patched within 48 hours? The disclosure of the issue can only mitigate so many things, and patch schedules by vendors is not one of them. If your vendor takes 3 months to patch the system, is that the requisite amount of time the researcher should be expected to wait before disclosure? That seems preposterous.
> > Do vendors want more time to fix things? Sure, they always will.
> That was never my argument. I never said they should get more time to fix things.
So then that is your argument. What is a reasonable amount of time, and why is your arbitrary value not arbitrary? A day, a week, a month, a year; when can you ever be sure you've reached the critical threshold of patched systems using a rule of thumb?