Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Oh boy someone's not going to have a fun long weekend


As the article says, the vulnerability was fixed in April and the people who discovered it have already been rewarded under Google's Vulnerability Reward Program. Google also proactively detected the problem before being notified by the researchers.


It's already been resolved by Google and is not exploitable, so yes hopefully sysadmins using SQL Server on CloudSQL will indeed have an actually fun long weekend.


It's responsibly disclosed after the hole is patched.


The term of art is "coordinated" disclosure. All sorts of disclosures, with or without vendor consent, can be "responsible", so we try not to use that term, which was coined as a device to give vendors power over researchers.


As a customer, I'm glad that both the vendor and the researcher are acting responsibly


But I got my pitchfork out and everything!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: