pull down to refresh

No dev is going to tell you how many vulns are in the pipeline before they are patched and (I guess this has become optional now) rolled out.

Right. A vague statement like this makes sense to me because it communicates to people that there’s a reasonable possibility that something’s wrong with their setup without putting them at risk by pointing attacks towards them.

reply

Exactly, though before the "responsible disclosure" process meant you completely stfu in public until it is patched. I do think that there is no point anymore. Even Linux kernel security people are arguing that it's better to say what's wrong straight away (and offer a mitigation) than to have an embargo.

Not everything will have a mitigation though.

reply