Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The vendor requested embargo timelines can get pretty crazy.

Intel requested an embargo for 21 months for SRBDS/Crosstalk.

For Downfall, a more recent one, Intel requested a 12 month embargo to release a microcode update.



For all I know, that might be a reasonable ask for these kinds of vulnerabilities --- not that researchers have to honor them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: