Privately disclosed to Apple, 90 days later they published. Simple as that.
Privately disclosed to Apple, 90 days later they published. Simple as that.
Is it perhaps possible that equitable treatments of vulnerabilities and companies might not be particularly high on the list of priorities for GPZ? Some might even argue that past attempts at equitable treatment have backfired badly, with many cases of companies abusing the time this gets them to not fix vulnerabilities.
Again, you're completely correct. Though I would genuinely love to hear your ideas of what equitable policy would look like - it could easily be better!
I understand the positive incentives for publishing when companies do not respond to flaws.
However Google has no particular right to police other companies.
If they disclose at 90 days, and harm ensues, there is no defense. Google is responsible.
The way you laid things out, Google should just collect zero-days and sit on them? Do you see the absurdity of that? From a business perspective, having these vulnerabilities around makes it easer for their competitors to collect the same kinds of data about internet search and private emails from people around the internet that Google collects from legit means. Getting vulnerabilities fixes widens Google's data moat.
Disclosing issues is not "policing". They are not arresting people, or taking any action other than stating the truth, that some software is vulnerable.
If they disclose at 90 days and harm ensues, the user bears responsibility for continuing to use the software. If they trust the software vendor to issue timely updates, then they can turn around and lay blame at the vendor for not fixing the issue. Or they can blame the hacker.
Some bugs may take longer than that to fix. I still don't think it's an unreasonable question to ask.
https://ics-cert.us-cert.gov/ICS-CERT-Vulnerability-Disclosu...
Google is being more than generous, doubling to 90 days.