None
NL
Too Many People Don’t Value the Time of Security Researchers
['View Archive']
Dhole Moments
This might sound obvious when I say it like that, but I’ve had many people respond to me disclosing a vulnerability disclosure with a demand to spend more of my time writing, testing, and submitting a patch to the project in scope. But when someone opens a report with, “I’m not looking for a bounty, this is where I was told to send reports,” it’s a little insulting to get the same treatment as the 10,000th “vulnerable to self-XSS via browser developer tools; pay bounty now” report that week. When most people say “responsible disclosure” they really mean “coordinated disclosure”, where the vendor pledges to fix the issue and release a new version before the vulnerability details are made public.