And it had the exact same automatic 90 day disclosure applied: https://bugs.chromium.org/p/chromium/issues/detail?id=944062
"Please note: this bug is subject to a 90 day disclosure deadline. After 90 days elapse or a patch has been made broadly available (whichever is earlier), the bug report will become visible to the public."
In fact they've reported a lot of Chrome vulnerabilities: https://bugs.chromium.org/p/project-zero/issues/list?colspec...
And Android ones: https://bugs.chromium.org/p/project-zero/issues/list?colspec...
Hey, look at that! Equal treatment for all.
Project Zero has long maintained that any serious company should be able to meet 90 day disclosure timeframe, and yet here comes Google+...
So it's not "literally no company". ;)
Disclosure: I work for Mozilla and I have reported a number of security bugs on our code, the vast majority of which are now public.
Regardless: that's a good point. I should have said, public disclosure of internal findings is not an industry norm. Mozilla is a good counterexample to the argument that everyone close-holds internal findings.
Of course, as you say, we do rate almost all security issues, and eventually make them public, so the information is only a bugzilla search away! https://bugzilla.mozilla.org/buglist.cgi?keywords=sec-critic...
How is that different?
Disclosure is one thing, remediation is another. The former is only instrumental to the latter. In the G+ leak, remediation was swift; so disclosure was not required.
(Btw, the affected accounts were 500K, reportedly, not millions.)