Stupidity
Stupidity
Posted May 9, 2026 10:14 UTC (Sat) by muase (subscriber, #178466)In reply to: Stupidity by jpeisach
Parent article: Dirty Frag: a zero-day universal Linux LPE
If you can reasonable assume that an exploit is unknown to others, it can make sense to keep it secret until patches deployed. However, if there is only a slight realistic chance that an exploit is known to other, less benevolent actors, it becomes paramount to thoroughly inform the users. You should give them all the information and tools so they can apply mitigations, do some risk analysis and tests for their specific setup, or even just identify and take vulnerable systems offline.
Intentionally not informing your users if your product puts them in danger is objectively malevolent behavior – up to the point that in other contexts that can even lead to legal consequences (rightfully so).
