That assumes you're the only one who knows about the bug so far. That is an irresponsible thing to assume.
-
-
In this day and age people buy and sell vulns and the NSAs of the world have an arsenal of 0days and holding onto bugs is just Wrong™.
1 reply 0 retweets 0 likes -
You seem to assume this info may get in the hands of anybody, but the set of reviewers is public and the association between paper and reviewer is not lost after submission. If exploit leaks the one responsible can be singled out. That’s a significant control mechanism
3 replies 0 retweets 1 like -
Replying to @securescientist @raistolo
I'm assuming someone may already know of this bug and be actively exploiting it. This is exactly the kind of ubiquitous bug govts love.
2 replies 0 retweets 0 likes -
So you must be angry at the silent “early” update not at the disclosure to an “academic review board”.
1 reply 0 retweets 1 like -
Replying to @securescientist @raistolo
I'm annoyed that disclosure to an academic review board (with zero benefit to security and low but nonzero risk of leak)...
1 reply 0 retweets 0 likes -
Happened two months before disclosure to the first vendors (which is what actually helps security).
1 reply 0 retweets 0 likes -
No. What helps security is the incentive to disclose. Bug bounties are that of sec res. Top confs are that of academics. With your rationale there would have been no disclosure (finding) at all. If you believe in discl for greater good go tell hackerone and co they’re pointless
2 replies 0 retweets 1 like -
Replying to @securescientist @raistolo
What? *Disclosure* helps security. *Incentivizing* that is one step removed from it. The paper is fine. Waiting two months isn't.
1 reply 0 retweets 0 likes -
This is all about timelines, not lololol security papers are useless. There are many good ones out there and most talk about vendor response
1 reply 0 retweets 0 likes
... because their authors were reasonable enough to start the disclosure process in *parallel*, not finish, submit, and wait 2 months!
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.