Disclosure timeline for vulnerabilities under active attack
googleonlinesecurity.blogspot.com
googleonlinesecurity.blogspot.com
(Compare this key quote: "Based on our experience, however, we believe that more urgent action -- within 7 days -- is appropriate for critical vulnerabilities under active exploitation.")
It is possible to improve many headlines, and despite the slightest twinge of editorializing added by the "...is enough..." wording, the submitted headline was both accurate and informative.
On a side note, I have a hard time taking any blog at a .blogspot.com domain seriously. Don't know why.
[1] https://github.com/blog/1466-yummy-cookies-across-domains
> If we receive a removal request that violates local law, that content may no longer be available to readers on local domains where those laws apply.
When I removed the .br part it redirected me to .blogspot.co.uk
It really is .br. but the last . is left of for convenience.
It may still be less damaging for only 'some' bad guys to be using the vulnerability, and continue to think that only they know it. (Thus, they use it sparingly). Immediate full disclosure means 'all' bad guys learn of the vulnerability, and then perhaps rush to maximally exploit (knowing they're in a race to use ASAP or lose their chance).
Are there any independent groups that rate a firm's response to an exploit? Other than HN comments and (rare) legal recourse, I don't know what pressure a YC startup faces to do a good job in a holistic sense. It'd be nice if a respected 3rd party were around to shame sites if necessary.