n-day speed has to be accepted

This normally takes a few days and a release within a week or two is reasonable. Within about ten minutes (!) this website was fielding probes for percent-encoded traversal sequences, indicating that automated watchers are keeping an eye on public repositories.

Anil Madhavapeddy, Just a rumour of a bug is enough to find a security exploit these days. Via Simon Willison.

the speed of n-day development has been independently validated enough times that it has to be accepted. i am also not sure exactly where we go. defense-in-depth is still our best bet. however, i think it will take a few high profile breaches before we face this. and it’s probably going to be in the next 6-12 months.

Pwn2Own Berlin hit maximum capacity for the first time in the contest’s history and closed submissions early. exploit production showed up as a scheduling constraint.

embargoes assume the details stay secret. at this point … a public PR, a mailing list hint, or a patch diff is easily enough search direction. scary stuff.