3 ms·
I don't know the reasons behind that policy, but I'd guess with the exploit already being used, there is less incentive to keep silent about the issue. The oppo
by Felk 7y ago
I don't know the reasons behind that policy, but I'd guess with the exploit already being used, there is less incentive to keep silent about the issue. The opposite is true: putting more pressure on the vendors to provide patches, and disclosing any malicious actions that are already underway as soon as possible
- mehrdadn 7y agoThey could tell vendors about the issue earlier without telling the rest of the world earlier though, can't they?
- ebiggers 7y agoWell, the longer that vulnerabilities are kept secret, the longer that users are unable to take any action to protect themselves, and the less incentive that vendors have to roll out fixes quickly and to prevent vulnerabilities in the first place. See the Project Zero disclosure FAQ: https://googleprojectzero.blogspot.com/p/vulnerability-disclosure-faq.html https://googleprojectzero.blogspot.com/p/vulnerability-discl...