The benefit to security of any disclosure policy tends to be inversely proportional to how loudly vendors cheer for it 
-
-
Replying to @ejcx_
What difference does it make for cloud software? Patch adoption there is effectively perfect, so doesn't seem like an issue, perhaps I'm missing the point.
0 replies 0 retweets 1 like -
Replying to @ejcx_
You can investigate as much as you like, don't see how this changes anything. I don't see how it benefits users to allow you to consider if you have regulatory obligations in private?
0 replies 0 retweets 0 likes
Replying to @ejcx_
Yes, most of the security industry is vendors. Do you think we should design policies to favour them, or users? Its rude to start a disclosure debate, what did you expect? Don't bring up politics at the dinner table of you don't like it.
2:04 PM - 7 Jan 2020
0 replies
0 retweets
2 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
