logoalt Hacker News

VladVladikoffyesterday at 8:34 PM2 repliesview on HN

Hey Xint Code / tylerni7 <https://news.ycombinator.com/threads?id=tylerni7>, maybe you should improve your disclosure process as well? Maybe make it mandatory for users of your tool?


Replies

john_strinlaiyesterday at 8:42 PM

they disclosed 30 days after the patch was merged in the thing they reported to.

its the same disclosure policy as google's project zero, and several other major players, so you should probably be trying to ping a lot more people

reporters should not be responsible for finding out and individually reporting to every downstream consumer. blame the kernel security team, who is in a much better position to coordinate notifications to individual distro security teams.

show 1 reply
tptacekyesterday at 9:32 PM

The security research community would run you out on a rail if you tried to take a successful research product and attach mandatory disclosure norms to it.

show 1 reply