• bss03@infosec.pub
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 days ago

    Responsible disclosure is a kindness; it is not required–especially if/when the vendor doesn’t act in good faith.

    MS shouldn’t be able to silence researchers, but that’s what the industry gets by voluntarily clustering around a single, proprietary service.

    I don’t think either party should be compelled to take (or reverse) any action.

    • motruck@lemmy.zip
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 days ago

      Exactly. Thank you Microsoft do more of this so we end up in a federated world.