Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Responsible disclosure generally means you tell the maintainers first before doing your splashy talk. Which appears to be what happened here since there is a cve, and we know mostly what was fixed. The talk would probably just go into nitty gritty details about how it was found and how its exploitable, stuff a skilled researcher would already be able to figure out based on what has already been publicly released.


idk I read that as "I found out about this from the abstract". Not sure if it was shared in advance


If people found out about this from an abstract, the fixed version wouldn't have already been pushed to distros, cves issued, etc by the time it was public. People would also be a lot more angsty about it.

Nothing about this suggests that it wasn't first privately disclosed to the glibc maintainers or that anything else improper happened.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: