Post B7pdyuxh24S6MoBKD2 by wolf480pl@mstdn.io
 (DIR) More posts by wolf480pl@mstdn.io
 (DIR) Post #B7pdyuldksoLlQXhQG by andrewnez@mastodon.social
       0 likes, 0 repeats
       
       Me: sitting on various security issues I’ve discovered because it would be irresponsible to disclose publiclySecurity companies: this would make a great blog post, regardless of if the vulnerability is still in the wild!
       
 (DIR) Post #B7pdyuxh24S6MoBKD2 by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @andrewnezI thought the standard practice was to give up to 90 days of embargo, assuming that if the vendor didn't release a fix in that time, the vendor is slacking, and the users deserve to know about the vuln.All of which presupposes that it's likely that an attacker could independently discover the same vuln as you did.
       
 (DIR) Post #B7peNAQNC7RxH09x56 by andrewnez@mastodon.social
       0 likes, 0 repeats
       
       @wolf480pl the vendor has upwards of 5k automated PRs on their repo, I can’t see me shaming them into fixing some serious design flaws
       
 (DIR) Post #B7peg16y2nWhtL4SdE by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @andrewnezand also, the process was designed for proprietary software vendors, not FOSS