All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Why the 90-day responsible disclosure policy is obsolete in the age of LLMs

By

Himanshu Anand

22d ago· 14 min readenOpinion

Summary

The article argues that the traditional 90-day responsible disclosure window for security vulnerabilities is obsolete in the age of LLMs. The author explains that AI tools have dramatically accelerated both bug discovery and exploit development, compressing timelines to near-zero. Drawing from firsthand experience and real-world examples, the author calls on the industry to treat every critical security issue as P0 (highest priority) and patch immediately, abandoning the old disclosure model that assumed slow exploit development.

Key quotes

· 4 pulled
The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone.
LLMs have compressed both timelines to near-zero.
treat every critical security issue as P0 and patch it immediately. Not tomorrow. Not next sprint. Now.
I have been doing security work for a while now, and the last 12 months feel different.
Snippet from the RSS feed
TLDR The 90 day responsible disclosure window was built for a world where bug finders were rare and exploit development was slow. That world is gone. LLMs have compressed both timelines to near-zero. I have seen it first hand, and so has everyone else pay

You might also wanna read