When vendors send cease & desist warnings just before they know a disclosure is to be made, it causes an interesting dilemma: if you think a vendor will resort to such tactics, do you simply not inform them of the impending release? Thoughts welcome. 
Replying to @ProfWoodward @hedgeberg
One strike policy. If they attempt to do this once, they forfeit the right to advance disclosure of any future vulnerabilities. This fact and the C&D should be documented for that vendor's customers to reference.
0 replies
1 retweet
13 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.