@fionafokus hmm, side-question, what makes it bad about publishing patches?
or: why does coordinated disclosure exist?(?) why does it matter that he published patches instead of following a disclosure timeline, we thought that was only a thing to avoid pissing off corporate entities/avoid lawsuits and CFAA charges?
@SoniEx2 @fionafokus
It is already explained in the blog post. If you notify instance admins in advance, without revealing details about the vulnerability, the time window in which the bug can be exploited should be shortened.