Improving the handling of embargoed hardware-security bugs
Improving the handling of embargoed hardware-security bugs
Posted Oct 25, 2018 19:45 UTC (Thu) by jhoblitt (subscriber, #77733)Parent article: Improving the handling of embargoed hardware-security bugs
Does a hardware vendor have any level of legal liability if they know of a *defect* and continue to sell defective components without disclosing it to the buyer? What about if the vendor is aware of a vulnerability and an end-user is victimized by the vulnerability?
I grasp that shipping a microcode update is unlikely to ever be an overnight process but is anyone really more "secure" because a vulnerability isn't disclosed to the "public" for 6 months? I think I'd rather be aware of a known risk rather than gamble that a exploit isn't already in the wild...