> Mr Cluley did add, however, that he thought the Project Zero protocol for announcing the vulnerability - which had included information that malicious hackers might have found useful - had been risky. > "That can help the bad guys," he said. This is just plain wrong, isn't it? I was under the impression that all of the details on PZ are hidden until either a fix is released, or 90 days have passed. I don't see how…
Yeah, I don't get this. The announcement on twitter contained zero information apart from "there's a remote code exec vulnerability on windows". Which I think you could confidently say at ANY point in time (about ANY system). But Graham and others ( https://twitter.com/taviso/status/861575086632968192 ) continue to attack Tavis for announcing the fact that there is a known vulnerability. As if this somehow makes user…
If being alerted allows organisations to prepare to patch, surely it also allows malicious actors to prepare to exploit?
My lay gut feeling is this seems more a trade-off in publicity between the announcing party and the software provider, both wanting to be seen with the initiative so that they look good.