logoalt Hacker News

jasonmp85yesterday at 6:51 PM6 repliesview on HN

Does it? Now that I see their name again in this context they're blacklisted for life.


Replies

john_strinlaiyesterday at 8:48 PM

hope you are also blacklisting google's project zero, and practically every other major player in the vulnerability reporting space, as all use roughly the same bog standard 90+30 policy.

this was a failure of the kernel security team, and their stance on communicating security issues with their downstreams.

bathtub365today at 1:54 AM

What are they blacklisted from exactly? The benefit you get from them forcing vendors to make their software more secure?

eaf7e281yesterday at 7:34 PM

Same. They do become famous, but not in a wholly positive way.

show 1 reply
selectivelyyesterday at 7:02 PM

Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.

show 11 replies
CSSeryesterday at 7:00 PM

Yes, exactly. Name and shame.

true_religionyesterday at 7:01 PM

Same. I did not know who they were, but now they have been named and shamed. Not every publicity is good.