A fuzzy issue of responsible disclosure
A fuzzy issue of responsible disclosure
Posted Aug 13, 2022 15:24 UTC (Sat) by mcatanzaro (subscriber, #93033)In reply to: A fuzzy issue of responsible disclosure by willy
Parent article: A fuzzy issue of responsible disclosure
Investigating and fixing bugs requires significant time and expertise over and beyond writing the fuzzer. A security bug report is an almost universally-appreciated contribution in any other project, and it's where security researchers are generally expected to stop. Going above and beyond to fix the bug is even better, of course, but if we expected researchers to do that for us, we would be much less secure because there would be far fewer bug reports, probably 50-100x fewer.
Besides: "Attackers have fuzzers too and know how to run them." Attackers are going to find these vulnerabilities regardless. Keeping the results hidden provides only minor benefit.
