> Governments have an obligation to protect the private data of its employees and citizens. In addition, the exposure of proprietary government data can be used for great means of manipulation and for other destructive purposes. Understandable. > While the NCIIPC operates a Responsible Vulnerability Disclosure Program, the recklessness and avoidance of communication represents the complete opposite of a responsible p…
> Why did they published anything about the vulnerabilities before they were absolutely sure all of those has been mitigated? Because various entities tried to exploit that to defer any publicaton, which lead to things never getting fixed. An entity may not want to fix things, but at some point their users / constituents have a right to know so they can take their own protective measures.
Also understandable.
> [...] so they can take their own protective measures.
Little can the ordinary citizen do whose data is at risk of exploitation. All responsibility lies on the government because the citizens do not have any other choice, as it seems to me. What protective measure can someone take who is vulnerable?
With a thorough reading of the article, it is clear that the hackers are aware of what they are doing:
> Once threat actors catch wind of major vulnerabilities against an organization they begin poking on their own, looking for more vectors of attack.