Someone wrote in [personal profile] mjg59 2019-07-10 09:08 pm (UTC)

90 Days

90 days is way too much time. The issue should be public the moment you find it if you want to responsibly disclose it. It's irresponsible to put people in risk longer than they have to.
>but what if the developer doesn't have a fix ready
Who cares? Just tell people to stop using the product.
>but then companies will lose users
Then don't make vulnerable software. It should be illegal to release software with major vulnerabilities. Maybe if these companies were punished hard enough they would actually invest into making secure software. The fact that vulnerabilities happen on a constant basis makes computer engineering a joke of the engineering professions.

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org