You would hope the self-described twitter bio "Agile Software Craftsman" might have thought about this a little before tweeting.
You would hope the self-described twitter bio "Agile Software Craftsman" might have thought about this a little before tweeting.
Since we're just making up statements, I guarantee that Apple would never voluntarily disclose this issue if it was reported privately. So Full Disclosure is the only way to put Apple's feet to the fire, as it's the only way in which this issue would have had any visibility whatsoever.
https://en.wikipedia.org/wiki/Full_disclosure_(computer_secu...
I think on the (probably intentionally snarky) basis of "just making up statements":
> Since we're just making up statements, I guarantee that Apple would never voluntarily disclose this issue if it was reported privately.
This guy is, with all probability, not the first one to have found it.
I'm not sure what length grace period is appropriate, though.
Same applies for Apple. No reason to believe this guy was the first one to find this exploit, we only know he was the first one to publicize it.
True, and this is where the analogy breaks down, since they would not be able to remotely send over a fix. But Apple would, and apparently now has.