This brings up the whole issue of when should a vulnerability be disclosed? When researchers find it or after a patch is issued? Software makers such as Microsoft, of course, don't want vulnerability information announced until they can announce they've fixed it, but seems like that position is a valid one.

Post new comment