42 ms·
You sure? Coordinated disclosure works like this. I find a vuln. I give you a timeline of my release. You accept that and work with me to acknowledge it and pre
by bitexploder 3y ago
You sure? Coordinated disclosure works like this. I find a vuln. I give you a timeline of my release. You accept that and work with me to acknowledge it and prepare your users. We negotiate release timing. Sometimes, if there is no evidence of exploitation we can push it out a little. If you stop communicating or act in bad faith I am doing whatever I want. You didn’t pay me and your users deserve to know. There are so many bad faith orgs that will try to avoid disclosure entirely or act downright hostile towards security researchers. Someone’s wires got crossed at JetBrains. Rapid 7 discloses a lot of vulnerabilities using this exact process. Many orgs use coordinated disclosure. They don’t all use the same timelines and processes, but those are the broad strokes. I have helped disclose many vulns using coordinated disclosure so I get where Rapid7 is coming from. It’s like this: It’s my vuln info. I will do whatever I want with it. I decided to give you my entire process and timeline to give you a chance to deal with it. You decided to ignore my “terms” and stop participating in the process. I am free to do what I want with the vuln now as I have exceeded my ethical obligations to help you.