https://hn.algolia.com/?query=author:tptacek%20responsible%2...
Anyways: hard no to the suggestion that, in order to be a "real researcher", you have to coordinate your disclosures. To be a serious researcher, you just have to be serious about finding vulnerabilities.
(Semantic reminder: our field uses the term "researcher" in a way closer to the journalism definition of the word than the academia definition.)
- Discovery didn't create the bug. You have no idea who has been exploiting the shit out of it already.
- Vendors will have all sorts of unreasonable responses, from ignoring you to threatening legal action to dragging their feet.
- Vulns are work product. You are entitled to zero of the researcher's time and effort unless you're paying them for it.
I'm not saying coordinated disclosure is bad either! I prefer to do it when I find stuff. We found a bug in NextJS last week and we did coordinated disclosure (I'm talking about it now because they released a fix). I'm saying the researcher owns the bug.
EDIT: Oh no! Of course he beat me to it.
People are needlessly at risk if they’re still using a vulnerable service they could have been told not to use while you wait for the vendor.