3 ms·
They are following their own practices first a foremost. Consider this policy by Google's Project Zero for example: >Project Zero follows a 90+30 disclosure d
by yegnau 3y ago
They are following their own practices first a foremost.
Consider this policy by Google's Project Zero for example:
>Project Zero follows a 90+30 disclosure deadline policy, which means that a vendor has 90 days after Project Zero notifies them about a security vulnerability to make a patch available to users. If they make a patch available within 90 days, Project Zero will publicly disclose details of the vulnerability 30 days after the patch has been made available to users.
https://googleprojectzero.blogspot.com/p/vulnerability-disclosure-policy.html https://googleprojectzero.blogspot.com/p/vulnerability-discl...
Rapid7's "we release full details and ready-made exploits the very day vendor releases a patch" seems to be an unnecessarily aggressive take on vuln disclosure. It benefits them as a for-profit security research firm, but definitely not the users who are given no time gap to apply the patches. All while any attacker of any skill level can start using the exploit against them.
- ziddoap 3y agoAs soon as a security patch is released, it will be reverse engineered and exploited, regardless of whether PoC code has been released. >Rapid7's "we release full details and ready-made exploits the very day vendor releases a patch" This is not their whole policy. They have exceptions, extensions, etc. But yes, they will publicly disclose a vuln if your company decides to refuse coordinated disclosure and choose to silent patch. They also don't release "ready-made exploits", please don't be hyperbolic. They release technical details about exploits, yes. But they aren't releasing metasploit modules or the likes... See also from Project Zero (assuming that is your preferred vendor?): >Any attacker with the resources and technical skills to turn a bug report into a reliable exploit chain would usually be able to build a similar exploit chain even if we had never disclosed the bug