27 ms·
As someone who doesn't work much with software teams, can someone fill in my gaps for understanding timeline. I'm imagining after a security issue is identifie
by Robelius 6y ago
As someone who doesn't work much with software teams, can someone fill in my gaps for understanding timeline.
I'm imagining after a security issue is identified, the steps taken are roughly in the below order and close-ish for the date. I guess my question is, why does it take 20 months from start to blog post?
-Contain the issue (1wk)
-Remove the threat (1wk)
-Build up remedies (a few months)
-Check and recheck what happened to make sure you're accurate when submitting final reports (a few months)
-Release a blog post (1month)
The timeline is a cool day by day instance, but I just don't understand the larger timeline.
- tclancy 6y agoI assume it's related directly to "It’s been quite some time since our last update but, after consultation with law enforcement, we’re now in a position to give more detail".
- kmontrose 6y agoIt's this. Discovery, immediate mitigation, deeper mitigation, general notice, notifying effected users - all these can happen pretty quickly once the ball is rolling. Once you're dealing with "the law" in any capacity you are constrained in what you details you can share broadly, and when. I'm happy we were finally able to share this level of detail.