Arguments ranging from 90-day embargoes being too long to 5-day ultimatums for companies. Some argue life-critical systems require faster response while others note complex fixes need engineering time.
← Back to AI is breaking two vulnerability cultures
The debate over security disclosure timelines centers on whether traditional 90-day embargoes remain viable in an era where AI can rapidly turn public code changes into exploits, potentially rendering long windows an "illusion" of safety. While radical perspectives argue for aggressive five-day ultimatums to force corporate accountability—suggesting companies should shut down services entirely if they cannot patch quickly—others maintain that complex architectural flaws require significant engineering time to resolve without breaking critical systems. This tension highlights a clash between the "bugs are bugs" culture of rapid, quiet patching and the necessity of coordinated disclosure for massive hardware-level vulnerabilities. Ultimately, the rise of automated discovery may be eroding the historical "guild ethic" of white-hat hacking, forcing a shift where immediate transparency is prioritized over the logistical convenience of software vendors.
7 comments tagged with this topic