Discussion about this post

User's avatar
TimothyTraddle's avatar

This is strong research, but the disclosure timing is hard to defend.

Publishing while the fix isn’t in a stable release means the vulnerability is public before most users have any practical way to protect themselves. That trade-off needs a clear justification.

Two weeks is too short to argue for meaningful uptake, and too short to justify early disclosure as a way to force action.

So what this effectively creates is a window where the vulnerability is widely known, but the fix isn’t realistically available to the people who need it.

There were better options — either wait until the fix is actually in users’ hands, or make a clear case for why early exposure was necessary. This does neither.

1 more comment...

No posts

Ready for more?