Updates to Google’s disclosure policy

Project Zero team at Google revises its disclosure policy after sensibly studying Project Zero’s disclosures data to date and taking on board some great debate and external feedback around some of the corner cases for disclosure deadlines. Changes to the policy include whether a deadline is due to expire on a weekend or US public holiday then the deadline will be moved to the next normal work day, and a 14-day grace period if the vendor informs the team that a patch is scheduled within 14 days following the deadline.

Read Google’s blog post here – http://googleprojectzero.blogspot.com/2015/02/feedback-and-data-driven-updates-to.html

Leave a Comment

Your email address will not be published.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Scroll to Top