Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And at other times 90 days maybe inadequately short. But 90 is just a round number someone at Google thought is a good idea. And now it's become 'standard'.

I can go with immediate, or I can go with never. But realize that every vuln is different, and their impact (or hardship of writing or applying patches) may not always be fully understood by stakeholders involved before or immediately after the details are released [CVE-2015-0235].

[CVE-2015-0235] https://nvd.nist.gov/vuln/detail/CVE-2015-0235



90 days is good amount of time to research a vuln and prepare fixes.

We could always have the government regulate this instead though, instead of being professionals and self-regulating.


And that would end so well. Nothing like infringing on the 1st Amendment (if you're in the USA).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: