Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Project Zero – Policy and Disclosure: 2020 Edition (googleprojectzero.blogspot.com)
32 points by esnard on Jan 7, 2020 | hide | past | favorite | 1 comment


Nutshell: where before P0 would disclose once a vulnerability was patched, or at 90 days, now it's simply "disclose at 90 days". If you patch on day 1, you still get 89 days of embargo (you can, of course, waive the embargo).

The rationale is to eliminate disincentive for rapid patching: previously, vendors had an incentive to hold their patch until the end of the embargo period, because patch release terminated that embargo. That's no longer the case: vendors can now patch right away, and use the remaining embargo days to evangelize the patch.

In addition, vendors can now patch iteratively, getting a hotfix out without disrupting the embargo and following up with a comprehensive or systemic patch later.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: