How do you negotiate an embargo window with a reporter, and what happens when it expires?
answer
- a date, not a milestone
- conventional defaults exist; know them
- argue from engineering, not calendars
- extensions: once, early, with a new date
- expiry hands control to the reporter
basics
~20 sAgree a specific calendar date early, justified by real engineering work rather than convenience. When the window expires the reporter is free to publish whatever they have, fix or no fix, so an unagreed overrun becomes full disclosure.
solid answer
~40 sGet a firm date in the first exchange, not "when the fix is ready". Ninety days is the common default in published research policies, coordinators run shorter defaults of their own, and distributor pre-notification lists are shorter still. Anchor on one of those and argue from the work: a fix needing a data migration, a hardware qualification cycle or several vendors in step is a real reason to ask for longer, whereas a release train or a marketing calendar is not. Ask once, with a concrete plan and a new hard date. If they refuse, plan for the original date, which usually means shipping a mitigation if the full fix will not land. At expiry the reporter can simply publish. Nothing stops them, and threatening them turns a coordinated report into a public one.
go deeper
Know that the window is agreed as a specific date, that around ninety days is a common default, and that when it ends the reporter may publish with or without a fix.
Explain how you would justify an extension with engineering evidence, why rolling extensions destroy trust, and why coordinators and distributor lists use much shorter windows than the vendor would like.
Demonstrate the miss-the-date play: warn early, ship a mitigation, publish a partial advisory on the agreed day, and keep the finder credited. Show that you plan the date as a commitment your release process can actually meet.
Own the standing policy. Decide the maximum window your organisation will ever ask for, who is authorised to agree a date, and how to keep legal and communications from turning a negotiation into a threat that costs you every future report.
## Fix the date first, argue about it second The single most useful thing you can do when a report lands is convert it into a calendar date within the first reply. "We will publish on the 14th" gives both sides something to plan against; "we will let you know when the fix is ready" is what reporters have learned to read as a stall, and it is the most common reason a coordinated report becomes an uncoordinated one. ## Where the numbers come from There is no universal window, but there are conventions and it helps to know roughly where they sit: - **Around ninety days** is the de facto norm many security research teams publish as their default, with a short grace period if a fix is imminent. - **Coordinators run their own, usually shorter, defaults** and will publish at the end of them whether or not every vendor is ready. CERT/CC's published default has historically been in the region of forty-five days. - **Distributor pre-notification lists are much shorter**, often capped near two weeks, because the risk of a leak rises with both the number of recipients and the length of the hold. These are starting positions, not entitlements. A one-line fix in a library does not need ninety days, and asking for it signals that you have not looked at the bug. ## What justifies a longer window Argue from engineering reality, and be specific: | A real reason | Why it lands | |---|---| | The fix changes stored data and needs a migration | Users must upgrade through a step that cannot be rushed safely | | Firmware or hardware with a qualification cycle | Build, sign and validation cycles are measured in weeks and cannot be compressed | | Several vendors ship the affected code | Everyone must be ready or the slowest one's users are exposed on day one | | The fix requires an API change consumers must adopt | Shipping the patch alone would not actually protect anyone | And what does not land: an internal release train, a product launch, a conference, an executive who wants the news later, or a team that has not started. Reporters have heard all of these, and using one burns the credibility you need for the extension you may genuinely require next time. ## Worked example A researcher reports an authentication flaw in a batch data-processing platform and offers forty-five days. The fix requires a schema change plus a migration path for existing installations, and engineering estimates a hundred and twenty days end to end. The productive move is not to ask for a hundred and twenty. It is to split the problem: ship a mitigation the platform's operators can apply immediately, publish on or near the original date with that mitigation and a clear statement that the full fix is scheduled, and give the reporter a dated plan for the remainder. That protects users faster than a four-month silence, and it respects a window the reporter chose for reasons of their own. ## Ask once, and ask early An extension request works when it arrives with three things: what has been done so far, what specifically remains, and a new hard date. It fails when it arrives two days before publication, when it has no new date attached, or when it is the second one. Rolling extensions are how a reporter concludes the process is not real. ## What actually happens at expiry The reporter publishes. That is the whole mechanism. There is no appeal and, absent a signed agreement, no legal lever, and every credible research policy states this in advance precisely so the vendor cannot claim surprise. Practically, three things follow: 1. **You lose the ability to shape the announcement.** The technical detail, and possibly a proof of concept, arrive on the reporter's terms. 2. **Your users learn from a third party.** Support and customer trust take the hit, and downstream distributors who were never pre-notified are caught flat. 3. **The next report may not come to you at all.** So plan the date as a commitment, not an aspiration. If it becomes clear you will miss it, tell the reporter before they have to ask, and go out on the date with whatever genuinely helps users, which may be a mitigation and a partial advisory rather than a complete fix. ## Keep the process warm Silence is what breaks embargoes far more often than disagreement. Acknowledge the report within a day or two, confirm reproduction, name a coordinator on your side, and send a short status note on a fixed cadence even when the news is "still building". Agree how the finder will be credited, and hold to it. The window is a negotiation, but the relationship is what makes the next one easier.
- The fix will clearly miss the agreed date. What do you do a week out?Tell the reporter before they ask, with what is done, what remains and a proposed new date, and offer a mitigation users can apply in the meantime. Then plan to publish on the original date anyway if they decline: an advisory with a workaround on the agreed day beats silence, because the reporter can and probably will publish regardless.
- How short is too short a window?Short enough that no fix can exist by publication, and it is a judgement not a number. A one-line fix in a library can honestly go in days. If a reporter insists on a window that makes any fix impossible, say so plainly with the engineering reason, offer the earliest achievable date, and prepare a mitigation, since arguing about fairness will not move them.
- Does agreeing an embargo mean you must wait for it before warning anyone?No. Inside the embargo you may still tell parties who need lead time to protect users, typically distributors who rebuild your code and, in multi-vendor cases, a coordinator. That is pre-notification, not disclosure, and it should be agreed with the reporter up front so nobody is surprised by who is on the list.
saying these in an interview costs you the question
- Answers 'when the fix is ready' instead of a date
- Asks for repeated rolling extensions
- Justifies a longer window with a release or launch calendar
- Assumes the reporter must wait past expiry
- Threatens the reporter to hold the embargo