communication
communication
Posted Jan 21, 2026 19:18 UTC (Wed) by Phantom_Hoover (subscriber, #167627)Parent article: Responses to gpg.fail
Given the long-rising tensions between FOSS maintainers and security researchers I really think the latter should be thinking carefully about branding vulnerability drops with names like ‘gpg.fail’. I get that this stuff was fun and punky back in the day but security now has a big, boring and serious compliance industry attached to it and maintainers are already cracking under the strain; they don’t need their work insulted on top of that. At the end of the day, vulnerability disclosures by themselves do *nothing* to make anyone safer: they depend on the labour of maintainers patching them to materialise any actual benefit. So these researchers are part of a collaborative effort, and I don’t address my colleagues by getting up on stage and slating them for their epic fails.
