(Replying to PARENT post)
That's because they patch within a couple of days and don't want their systems unpatched for long (30 to 60 days!) when there is a known issue out in the wild. The flaws tend to get leaked, the temptation is big because there are huge money incentives.
I bet if the embargo were for 5 days they would reconsider. But good luck with that with members like Microsoft, Cisco, Oracle, which a terrible reputation of postponing things the maximum possible.
๐คalecco๐10y๐ผ0๐จ๏ธ0
(Replying to PARENT post)
That is true. OpenBSD/Theo refuses to take part in embargos, which means they don't get a heads up. Don't have a citation right now, but Theo said that publicly when Hardbleed or so happened.
๐คBluerise๐10y๐ผ0๐จ๏ธ0
(Replying to PARENT post)
In which case and assuming that is accurate then
> Why? Well, they just don't. That's the whole story.
Could have been
> Why? Well, we'd have liked to but they don't embargo reported bugs and we do.
Clearer for everyone.
Assuming it's true.
๐คnoir_lord๐10y๐ผ0๐จ๏ธ0
(Replying to PARENT post)
[1] https://news.ycombinator.com/item?id=9216815