This sounds like it would introduce a massive conflict of interest.
Also it assumes the OpenSSL team are the first to know about vulnerabilities. Heartbleed has shown that's not always the case.
Also it assumes the OpenSSL team are the first to know about vulnerabilities. Heartbleed has shown that's not always the case.
No comments yet.