Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.


Avoiding surprise was one of the principles in Section 2. To that end, explicitly declared policies (from both researchers and vendors) are a good thing. Expected disclosure timing is an important question to ask whenever a report is received. Sometimes the reporter or coordinator acting on the reporter's behalf has a standing policy of X days with no exceptions. Other reporters may be more flexible. If in doubt, ask.

All Agreements Are Contingent

When vendors and reporters negotiate and agree to a release timeline for a vulnerability, they often behave as if they've reached some state of détente with the world. But that's an illusion. They may have reached an agreement with each other, but it ignores another relevant role in the disclosure process: the adversary. Adversaries do not care whether the vendor plans to release the patch in a month, whether they need more time to test it prior to release, whether the reporter wants to break the news at a conference event, whether the reporter hopes to get paid for the work, or any other reason that reporters and vendors may have for agreeing to the terms they came to. Therefore it's important for vendors, reporters, and coordinators alike to recognize that all disclosure agreements are necessarily contingent on circumstances beyond the control of the parties involved; and that those circumstances are not simply random events but may be controlled by actors who are indifferent to their concerns. 

Diverting from the Plan

Je n'ai jamais eu un plan d'opérations.