Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To anyone who still thinks a 90-days deadline (with up to 14 additional days for patch release alignment) isn't fair enough, I invite you to look at the timeline for this report:

https://blog.quarkslab.com/reverse-engineering-broadcom-wire...

This is is remote code exec on any device. Yet without hard deadlines, vendors stall, lie, etc. This isn't the first example of this. There has been many throughout the past. Project Zero's policy is actually very well thought, and state of the art IMHO.



Quite frankly, a multi billion dollar software company like Microsoft should be ashamed of themselves for not fixing a 0-day in 90 days. Even with all the non-coding involved and rolling it out properly they should probably be ashamed if they can't do it in a week.


How about not putting the flaw in in the first place?


Who writes perfect code? Generally speaking, I find the more people working on a single codebase the more chance you have for introducing flaws.


There are many examples of near perfect code.


Yet you did not name examples?


How about NaCl and basically almost everything made by DJB?


I think it is fair and necessary as an incentive to immediately start working on it. It is also right to publish them after 90 days. I just think it is not fair to blame or make fun of companies for failing on delivery within 90 days what happens here regularly (see: upvotes for the article).

When developing a low risk application with a fancy DevOps infrastructure everyone expect bug fix delivery in hours or maximum the 2 weeks sprint.

90 days is not much time when patching operating systems or mission critical software. Windows is used in literally all regulated environments, from aircrafts to medical devices. The amount of necessary paper work and the amount testing to reduce risk is beyond what anyone not in that business can imagine.


> I just think it is not fair to blame or make fun of companies for failing on delivery within 90 days what happens here regularly (see: upvotes for the article).

Are people upvoting just to "make fun" of Microsoft? I assumed it was for visibility or to share an interesting insight into the inner workings of the security industry.


Yeah, but security incidents like that happen every month. We should be long bored of it.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: