Hacker News new | past | comments | ask | show | jobs | submit login

While it may not be the case in this scenario (since Sam says in a response on here that he sent them a message a few days ago), everyone should always be responsible in how they disclose flaws or discoveries in software:

http://en.wikipedia.org/wiki/Responsible_disclosure




> So just as giving a vendor no time to fix a vulnerability is irresponsible, so is it even more irresponsible to give that vendor a blank rain check.

http://kevtownsend.wordpress.com/2012/09/01/java-vulnerabili...


I don't think responsible disclosure applies to deliberate, already-public protocol decisions.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: