Releasing an exploit proof of concept is a hot debate. Some argue it’s educational, but it can also empower malicious actors. We see bulk exploitation rates explode after, but advanced compromises against key victims don’t change a lot. What’s your take?

Follow

@RGB_Lights It depends on how soon the POC is released after the vendor fixes. I see a number of research reports 30, 60, 90 days after vendor publishes advisory. This seems reasonable. The ones that really concern me is where POC are published when vendor does not respond to researcher report. User/owners pay the consequences for poof vendor response.

@RGB_Lights hmmm typo - should have been 'poor vendor response' not 'poof'.... Then again....

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.