logoalt Hacker News

0x0yesterday at 8:44 PM3 repliesview on HN

Dropping a public exploit on github before distros have patches available isn't very cool, or is that just how veterans roll these days?


Replies

tptacekyesterday at 9:11 PM

There is no one accepted set of norms on disclosure. Any strategy you take, someone will criticize.

akerl_yesterday at 9:09 PM

I don’t know if “cool” is the word I’d use, but there isn’t an established “right” way to disclose a vulnerability that you found outside of a contracted security review or other employment/contracting arrangement.

john_strinlaiyesterday at 10:29 PM

mainline was patched a month ago