9 ms·
Everyone has their coordinated disclosure policies, but not all of them are as harsh as Rapid7's. You mentioned Project Zero, it's a great example: >Project Ze
by yegnau 3y ago
Everyone has their coordinated disclosure policies, but not all of them are as harsh as Rapid7's. You mentioned Project Zero, it's a great example:
>Project Zero follows a 90+30 disclosure deadline policy, which means that a vendor has 90 days after Project Zero notifies them about a security vulnerability to make a patch available to users. If they make a patch available within 90 days, Project Zero will publicly disclose details of the vulnerability 30 days after the patch has been made available to users.
https://googleprojectzero.blogspot.com/p/vulnerability-disclosure-policy.html https://googleprojectzero.blogspot.com/p/vulnerability-discl...
Giving vendors 30 days after a fix is a much more user-friendly thing to do then releasing ready-made exploits simultaneously with a patch, isn't it?
- bitexploder 3y agoYes, I agree, but Rapid7 does not normally do that. https://www.rapid7.com/security/disclosure/ https://www.rapid7.com/security/disclosure/ “ If the responsible organization is showing consistent good-faith effort to develop and ship an update, but cannot complete this work within 60 days, a 30-day extension may be granted at Rapid7’s sole discretion under the Default Policy (or for any of the enumerated exceptions below).” They do this with good faith as far as I have seen. The issue as I see it is that JetBrains decided to stop communicating, eliminating the “good faith” on their end.