Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Seems innocuous, but maybe they were planning further changes.

Seems like an attempt to get 90 days of "use" of this vulnerability after discovery. If they only had checked performance before!



No, they just removed the bullet points about what to include in a report. The 90 days part was in both versions.


Yes. An incomplete report allows for dragging out "fixing" the issue longer.


True, but the "talk only to me" part was new, I think.


They didn't add any content, it was a pure removal commit




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: