Originally Posted by drgonzalez94
That seems impractical, honestly. This is a zero-day method, and we don't have any information about what exactly this exploit is capable of doing, or the security concerns that may arise as a result. I imagine that if you were to report it, they'd turn right back around and ask "Well where did you hear about it?" and "What is this exploit?" and that would be a compromising position to be in as you shouldn't answer the first question  and don't know the answer to the second. I applaud Branch Delay for being so mature about this, and contacting the vendor first. That is a very honest thing to do. 
|