4 ms·
That makes it OK for you to not responsibly disclose a vuln? Cool I guess)
by throwaway290 6mo ago
That makes it OK for you to not responsibly disclose a vuln? Cool I guess)
- concinds 6mo agoI have nothing to do with any of this. But since they don't consider these as vulnerabilities in the first place, then yeah, sure.
- bl4kers 6mo agoIt's very common for large companies to "close" or downplay vulnerabilities. That doesn't exempt researchers from responsible disclosure timelines. There have been plenty of instances where a company reverses course after some back & forth and the looming threat of going public.
- throwaway290 6mo agoYou literally made a statement justifying not responsibly disclosing vuln because apple process sucks whether it is a vuln is different argument (it's sandbox escape and definitely usable as part of an exploit)