Hey cyber security peeps, is there some sort of best practice or algorithm for determining *how long* one should give a corporate entity after notifying them of a serious security issue before going public about it?

@siderea I think it depends on how wary you are of corporations deciding to drag you through the courts.

If you don’t care about that, then perhaps Google Project Zero’s policy is appropriate. https://googleprojectzero.blogspot.com/p/vulnerability-disclosure-faq.html

Vulnerability Disclosure FAQ

Published: 2019-07-31 Last updated: 2021-11-29 Project Zero follows Google’s vulnerability disclosure policy  on all of our vulnerab...

@samir @siderea pretty much this, it depends on how you found it, how easily discoverable you think it is, and if you have reason to believe it's being exploited by anyone else.

In the last case, Google's 7-day policy is generous.