the 90 day disclosure policy is dead (opens in new tab)
The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone. LLMs have compressed both timelines to near-zero. I have seen it first hand, and so has everyone else paying attention. This post lays out why the old model is broken, […] The post the 90 day disclosure policy is dead appeared first on OODAloop.
Read the original article