It does harm - it adds 2+ months to the vulnerability window. At the very least you should be sending drafts of the paper out to vendors.
What? *Disclosure* helps security. *Incentivizing* that is one step removed from it. The paper is fine. Waiting two months isn't.
-
-
This is all about timelines, not lololol security papers are useless. There are many good ones out there and most talk about vendor response
-
... because their authors were reasonable enough to start the disclosure process in *parallel*, not finish, submit, and wait 2 months!
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.