3 ms·
Oh really? Lets say an issue meets the reporting criteria but a patch can only be deployed physically. And the exploit is a trival wireless attack on a pacema
by barelysapient 3y ago
Oh really? Lets say an issue meets the reporting criteria but a patch can only be deployed physically. And the exploit is a trival wireless attack on a pacemaker. By your reasoning, making sure everyone knows about the issue is a desirable goal? Come on.
There has to be nuance. Things that might _literally_ kill people probably shouldn't be reported the in the same way as a bug in a 15-year-old ink-jet printer driver.
- aaomidi 3y ago> There has to be nuance. Things that might _literally_ kill people probably shouldn't be reported the in the same way as a bug in a 15-year-old ink-jet printer driver. The problem is, its actively being exploited. You're just keeping systems and people uninformed and unable to make mitigations.
- Arnt 3y agoThe only party that's sure to know the vulnerability and exploit is the exploiter. On the day the software vendor/operator learns that the vulnerability and/or exploit exists, the vendor may not know much more than "a vulnerability exists" (e.g. if the vendor discovers it by seeing data exfiltration). Who would you require, by law to inform people?