Should the title be updated to reflect that this is 2+ months old? After all, the fix was put in place in a couple of hours. This isn't a current bug, but rather, an excellent post-mortem, but the title suggests present tense.
The write up is from yesterday about a bug fixed a while back, as per responsible disclosure.
Most responsible disclosure is normally posted about sooner though. I think what the OP meant is that waiting 2 months later, and then giving the post this title, makes it seem as though it was a more recent bug
Actually I waited until we pushed Pyxio website on-line.
Since I am not native English speaker, what would be best replacement for current title?
"Post-mortem" is usually appended to titles for solved vulnerabilities, although this was 2 months ago. Maybe just timestamp it? e.g. "Facebook CSRF leading to full account takeover (Post-mortem, August 2013)"
That would imply that the Post-Mortem itself was written in August 2013, which would probably get far fewer clicks as people assume they've read about the vulnerability before.
Do you really expect to learn about open bugs by reading HN?
Anyone who writes about security bugs like this where it's a "current bug" is being shitty. Follow responsible disclosure, people.
If you read the OP, you'll find that's what happened.
Oh I agree. I was directing my comment at the comment I replied to, which was bemoaning that this wasn't a current bug. It was like they were complaining that responsible disclosure wasn't followed.
I wasn't at all suggesting disclosing a bug before it's fixed. The write-up was great, the disclosure correct. I was merely saying that the HN title should reflect the current state of affairs.