Why are those channels “proper”?
TL;DR: Working for a billion dollar company does not magically give you anti-security issue super powers as much as we would like it to. If private disclosure makes sense for OSS, it makes sense for private companies as well.
-
-
You're drawing a private-company vs OSS distinction that I am not. I'm talking about this specific case and it has more to do with the widespread use of operating sytems, lack of updates being heeded, and the fact that this vuln was public already.
-
All I knew about was the forum post. I'm not well informed enough about how public it was to really make an informed opinion about this specific case it seems.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.