Protip: academic board observed secret and so did vendors. The OpenBSD patch went unnoticed. It was the Infosec community that screwed up.https://twitter.com/marcan42/status/919972354947796993 …
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
It does harm - it adds 2+ months to the vulnerability window. At the very least you should be sending drafts of the paper out to vendors.
Finishing the paper, sending it in for review, *waiting 2 damn months* then casually starting to notify vendors is utterly ridiculous.
The two months do not add to nothing. You should try reading the ISO standards and some prior debate on disclosure.
Nope, it doesn’t. Academic review of these papers happens under secrecy (this was NOT leaked in the academic review process).
That assumes you're the only one who knows about the bug so far. That is an irresponsible thing to assume.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.