嗨 @dhigby ,這不是我的本意。我只是想詢問,如果有首選方式的話,該如何回報發現的安全漏洞。
有時,安全漏洞的認定存在爭議,並非所有回報都屬實。為了避免向潛在攻擊者洩露漏洞,回報必須私下進行。如果漏洞未被修復,負責任的披露將轉為公開披露,以便用戶在可能的情况下採取措施保護自己。此討論串並非對漏洞的公開披露。
Hi @dhigby , that was not my intention. I was merely asking about the preferred way of reporting a discovered security vulnerability, if there was one.
Sometimes, security vulnerabilities are debatable, and not all reports are valid. Reports need to be made privately, to prevent disclosing the vulnerability to potential attackers. If the vulnerability is not fixed, responsible disclosure becomes public disclosure, so that users can take measures to protect themselves, if possible. This thread is not a public disclosure of a vulnerability.
機器翻譯自 English