Quote:
Originally Posted by knc1
Individuals threatening a billion dollar corporation is usually a poor strategy.
Your more likely to stay dry, pissing into the wind, than sway a large corporation with threats.
We are not waiting until they issue a fix,
we are waiting a "reasonable length of time" (in the author's judgement as to what is "reasonable").
|
There are
industry standards for responsible disclosure of security bugs. The time allowed for a patch varies from 45 days to 3 months or more. It is irresponsible and inaccurate to label these as 'threats', and this mechanism
does work in stimulating a response to the defects discovered.