Full Disclosure
Full Disclosure
Sofortige Vollveröffentlichung von Schwachstellen
Full disclosure denotes the practice of making all details of a vulnerability public immediately and completely — with no grace period for the vendor. Its proponents argue for transparency and maximum pressure for a quick fix; critics point to the risk of handing attackers a ready-made template. It is the radical opposite of coordinated disclosure.
History & facts. Full disclosure arose from distrust of vendors who in the past often ignored or covered up reported flaws — the stance became known through relevant mailing lists. The core argument: as long as only attackers and the vendor know about a flaw, defenders are at a disadvantage; full transparency creates a level playing field and forces speed. The downside is the phase of heightened exposure between publication and patch.
Outlook & recommendation. In practice coordinated disclosure (CVD) has prevailed as the standard, often with a fixed deadline as a compromise. Pure full disclosure is the exception today — for instance as a last resort when a vendor fails to respond over a long period. For organisations the lesson is to be able to react very quickly to vulnerabilities that have become public, because the clock starts at publication.