3 ms·
It's the trolley problem. If you don't disclose the vulnerability, users are potentially open to attack because you didn't tell them about a vulnerability that
by codexb 3y ago
It's the trolley problem.
If you don't disclose the vulnerability, users are potentially open to attack because you didn't tell them about a vulnerability that you knew about. If you do disclose the vulnerability, you potentially alert attackers to take advantage of a vulnerability in the short time before users can address it.
From the perspective of someone discovering a vulnerability, disclosing it is the more ethical thing to do because users should know that they are vulnerable and have the opportunity to prevent harm to themselves, even if it means making a service unavailable or degraded for a short period. If you tell them about it and they are attacked, that's on them. If you don't tell them and they are attacked, that's kind of on you.
I agree there's some grey area if there no known exploits, but a lot of times these vulnerabilities are found in response to an actual out-in-the-wild exploit.