logoalt Hacker News

MatthewWilkestoday at 6:50 AM2 repliesview on HN

I think very few people would consider that to be responsible disclosure. The common practice is to allow 90 days as a minimum.


Replies

rustyhancocktoday at 11:09 AM

I think I'd personally develop a minimal patch and then publically disclose.

I'm not sure it's be reasonable to leave an actively exploited critical bug until August. Nor would I be too interested in playing middle man or paying for support from curl to get it out.

akerl_today at 3:49 PM

Reminder that what you're describing is "coordinated disclosure", and that there are in fact plenty of people who consider "full disclosure" to be preferable in some or all cases.