back

by rdl·16y ago·view on hn ↗
The problem with "responsible disclosure" is that a vendor can convince you not to disclose at all -- they can drag out the process of patching for months, and can try to convince you never to release the disclosure, or at least to wait until no one cares anymore, because some users may not have patched.

The purpose of disclosure is twofold: you want the vendor to fix the bug, but you also want the marketplace to take notice of the existence of the bug.

Knowing that Vendor M was informed of a bug and took 6 months to fix it, whereas Vendor L was informed of a bug and took 1 day to fix it, is useful to me when I'm evaluating an operating system vendor. The best way to have this information out there is to cause a big splash when you release it.

Fundamentally, the assumption is that white and gray hat hackers do not discover every bug out there. If you sit there and do semi-sophisticated static analysis on a lot of software, or fuzzing, you can discover a lot of 0-day vulnerabilities which no one has yet announced.

If end users don't feel pain from security vulnerabilities, they will not prioritize adequate security when they make purchasing decisions. Vendors with a strong security focus should support aggressive full disclosure of all vulnerabilities of all vendors.