Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Google (Project Zero) has found and published plenty of vulnerabilities in Microsoft products.


(Part of) HN got real salty after Google auto-published after the 90-day disclosure deadline expired,but before MS had a patch out. I wonder what the reaction would be if Project Zero adopted a 24-hour disclosure...


What was this on?


I believe it was for this remotely exploitable IE/Edge[1] bug.

1. https://arstechnica.com/information-technology/2017/02/high-...


There is a difference in helping and destroying competition.


If it's factually correct it wouldn't be libel.

I wouldn't be surprised if it's illegal somewhere in the world, but in the US, publishing factual information you have not signed away the right to publish via an NDA or similar contract is usually legal. I don't know that motive is ever involved as part of the test of determining whether or not you are allowed to write something.

I'm not a lawyer, this isn't legal advice.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: