Now they can hide it for months(ever) allowing others to discover them and keeping the researchers quiet.
Now they can hide it for months(ever) allowing others to discover them and keeping the researchers quiet.
- Researcher finds bug
- Researcher discloses to vendor
- Vendor fixes (or not)
- Researcher discloses bug publically once vendor has fixed, or after X time (whichever is first)
This is roughly how Project Zero goes, and it's a good mix between giving the vendor the opportinity to fix it and deploy the update before it gets exploited.
It's very naive to assume that bugs can be fixed before others can exploit them. Bugs take time to fix, and the process takes time, especially when dealing with large enterprises.
The vendor can also usually request an extension, as per the Project Zero guidelines, of I believe 1 month if they confirm to be actively working on a patch.
The goal of responsible disclosure is to help the vendor and their users' be more secure, so having a policy that is balence between the two is important to let the vendor fix it, and to not let the users be possibly hacked
If so, that seems like a superior alternative to immediate public disclosure.