4 ms·
The common practice is to hold off disclosure until a patch is ready and has been tested, that way competent organizations will be able to jump on the problem a
by c2h5oh 3y ago
The common practice is to hold off disclosure until a patch is ready and has been tested, that way competent organizations will be able to jump on the problem and patch ASAP.
If you release a patch without disclosure there is a good chance many competent organizations will hold off applying it waiting for others to be the canary.
Releasing a patch and mentioning it fixes security issues while delaying vulnerability details is not much better - malicious actors with enough resources will figure out what has been changed and where the problem is. At the same time there will be a strong incentive to downplay the severity.