Earlier quoted context omitted.
> Is that a rule? No, it's commonly followed practice: https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc... I'm all for lighting a fire under the developer's ass, but we live in an imperfect world and the biggest problem that we have is end-users. We may have applied the mitigation on day 0, and updated as soon as the kernel landed in our distro - and if some of us didn't then we've even got savvy users in…
> For reference, the standard is 30 for the developer to fix and 90 for it to land on machines no, the standard is 90 days from notification or 30 days from the patch date, typically whichever is sooner . e.g. > If a vendor patches a security issue 47 days after Project Zero notified > the vendor about the vulnerability, details would be made public on day 77. > If a vendor patches a security issue 83 days after Proj…
> There is no such thing as "the responsible disclosure protocol".
And yes, I admit I got dragged down to their level and beat myself with a dumb stick in the process.