Some commenters advocate for full disclosure over coordinated disclosure, arguing delay benefits corporations over users and that immediate disclosure allows system operators to implement mitigations beyond patching.
← Back to AI is breaking two vulnerability cultures
Commenters argue that traditional coordinated disclosure is an increasingly obsolete model that prioritizes corporate convenience over user safety, particularly as AI tools now allow for the near-instant transformation of code commits into actionable exploits. By shifting toward a philosophy of full disclosure, proponents believe system operators are empowered to implement immediate manual mitigations—such as disabling specific modules or changing permissions—rather than waiting passively for an official patch. This perspective rejects the standard 90-day window as a tool for corporate foot-dragging, asserting that the financial and operational risks of insecure code should fall squarely on the providers rather than leaving users in the dark. Ultimately, the consensus suggests that in an era of radical software transparency, immediate public awareness is the only way to force genuine accountability and protect the end user.
8 comments tagged with this topic