Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From a high level, divulging the details could lead to the hole being patched up. Not having the details requires a much more thorough study being done to find out what happened.

i.e. if someone reports a working exploit for Chrome, but doesn't tell how, Google has no choice but to investigate as deeply as it can and root out any possibility it can think of, and perhaps do automated checks in all of the source where it could possibly happen.

If you instead point out it's a buffer overrun in file x.c, they'll likely just patch up that one file.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: