Yeah, this is the part I hadn't really considered when writing it.
Announcing that something is wrong before operators actually have the binary changes the threat model by itself. You've basically told everyone where to start looking while defenders still have nothing to deploy.
So the 14-day embargo may not even be the most interesting part here. The timing of the announcement vs the availability of the fix might be.
Definitely something I'll revisit once the source drops. Thanks for adding this.
Yeah, this is the part I hadn't really considered when writing it.
Announcing that something is wrong before operators actually have the binary changes the threat model by itself. You've basically told everyone where to start looking while defenders still have nothing to deploy.
So the 14-day embargo may not even be the most interesting part here. The timing of the announcement vs the availability of the fix might be.
Definitely something I'll revisit once the source drops. Thanks for adding this.