skip to content

Coordinated Disclosure Embargo

Agreeing a fix window, pre-notifying distributors and big consumers, and judging when a leak or in-the-wild use forces early publication. Interviewers want the judgement, not the etiquette.

on this pageshow

questions

5

What is coordinated vulnerability disclosure, and how does it differ from full disclosure?

level: juniorimportance: must knowfreq 66%

answer

  1. who learns about the bug, and when
  2. a private report buys a fixed window
  3. the window has a name
  4. publish now versus publish on a date
  5. held by reputation, not by law

basics

~20 s

Coordinated disclosure means the finder reports privately and gives the maintainer an agreed window to ship a fix before details go public. That window is the embargo. Full disclosure publishes the details straight away, with no window.

solid answer

~50 s

In coordinated vulnerability disclosure the finder reports the flaw privately, and the finder and the maintainer agree a date on which the details become public. The gap between report and publication is the embargo, and its point is that a fix should be available at the moment users learn they need one. Full disclosure skips the window entirely: the details are published immediately, on the argument that users can then defend themselves and that vendors only move under public pressure. Neither is a legal arrangement. An embargo is a promise between two parties, held together by norms and reputation, so a maintainer keeps it by shipping on the agreed date and keeping the reporter informed. A third behaviour, silently patching and telling nobody, is worse than either: downstream consumers cannot tell they need to upgrade.

go deeper

for a junior

Be ready to define both models in one sentence each and name the embargo as the agreed gap between private report and publication. Knowing that it is an agreement rather than a legal control is the part most candidates miss.

for a middle

Explain the mechanics: what each side gets from the trade, why silent patching harms downstream consumers, and why an embargo without a fixed date is effectively a refusal.

for a senior

Show you have run one. Talk about acknowledging fast, giving the reporter real status, holding the date you agreed, and recognising the moment evidence of exploitation makes holding pointless.

for a principal

Own the policy: what your organisation promises finders in writing, how you keep legal from turning reports into threats, and how you make the published window realistic against your own release engineering rather than aspirational.

## The three things a finder can do Someone finds a security flaw in software you maintain. They have three broad options. **Full disclosure.** Publish everything immediately, often including a working proof of concept. The argument is that users have a right to know they are exposed, that defenders can then apply their own mitigations, and that vendors historically only fixed things once the report was public. The cost is that every user is exposed during the window in which no fix exists. **Coordinated disclosure (CVD).** Report privately, agree a publication date with the maintainer, and hold the details until then. The intent is that patch availability and exploit knowledge arrive at the same moment, so the window in which attackers know something defenders cannot fix is as short as possible. The older name for this is *responsible disclosure*, a term largely retired because it implied that a finder who published was irresponsible. **Non-disclosure.** Tell nobody, or tell only a buyer. Or, on the maintainer's side, quietly fix the bug in a routine release and never say it was a security fix. Silent patching looks tidy and is the worst of the options for consumers: downstream users and their scanners have no signal that this upgrade is the urgent one, and an attacker who diffs your releases will find the fix anyway. ## What the embargo actually is The embargo is the agreed period between the private report and public disclosure. Two things about it surprise people: - **It is not a contract.** Unless someone signed something, a reporter is free to publish at any time, and most published research policies say exactly that. The embargo holds because breaking it costs the breaker reputation, not because it can be enforced. - **It does not start the exposure.** The flaw already existed and someone else may already know it. The embargo clock measures your response time, not the users' safety. If you find evidence of exploitation in the wild during an embargo, the reason for holding has evaporated. ## Why each side agrees to it The maintainer gets time to build, test and release a fix, and to warn the parties who need to rebuild on top of it. The finder gets a fix that actually protects the users they were worried about, plus credit and a clean public record. That trade only works if both sides deliver: the maintainer acknowledges the report quickly, gives a real status update rather than silence, agrees a firm date rather than "when it is ready", and ships on it. A maintainer who goes quiet for two months converts a coordinated reporter into a full-disclosure one, and deserves to. ## Who else can be in the room When more than one vendor ships the affected code, the two-party model stops working and a neutral coordinator is used. National and sector CERTs, most visibly CERT/CC, run this as a service: they hold the details, decide who else must be told, chase unresponsive vendors, and set the date. Distributors who repackage the affected component are pre-notified inside the embargo so their rebuilt packages land on the same day as the upstream release. ## The published process standards Two ISO/IEC standards describe this work and are worth naming in an interview: **29147** covers vulnerability disclosure, meaning how an organisation receives reports from outside and publishes information about them, and **30111** covers vulnerability handling, meaning the internal process that triages and fixes what comes in. They describe the shape of the process, not the content of any one advisory. ## The mistakes that show inexperience - Treating the report as an attack and the reporter as an intruder. Legal threats against finders are the fastest known way to guarantee full disclosure next time, and they teach every other finder to stay anonymous or say nothing. - Asking for an indefinite embargo. "Hold it until we release" with no date is a refusal dressed as a request. - Believing the embargo protects users. It protects the *fix rollout*. Users are exposed the entire time; that is precisely why the window should be as short as the fix allows and no longer. - Confusing this with internal incident handling. Coordinated disclosure is about a flaw in software you ship to other people. It runs on its own clock and produces a public artefact.

  • Why has the industry mostly stopped saying 'responsible disclosure'?
    Because the word put the moral burden entirely on the finder: anything other than waiting indefinitely for the vendor could be labelled irresponsible. 'Coordinated' describes the same practice without the judgement, and makes it clear the obligation is mutual, since a vendor who ignores a report for months is the party failing to coordinate.
  • A maintainer wants to fix the bug quietly and never publish anything. What is wrong with that?
    Consumers cannot tell the release is urgent, so they patch on their normal cadence while the fix is already public in the source diff for anyone comparing versions. Silent patching also breaks downstream tooling, which matches advisories against versions and will keep reporting them as safe. It trades a short embarrassment for a long, invisible exposure.
  • If the embargo is not legally binding, what makes it hold?
    Reputation and reciprocity. A finder who breaks embargo stops being trusted with early details; a vendor who misses agreed dates stops receiving private reports at all. Where stronger assurance is genuinely needed, such as pre-notifying commercial partners, parties sign an agreement, but the everyday open-source embargo rests entirely on norms.

It is the difference between telling a landlord the lock is broken and giving them a fortnight, and pinning a note about the broken lock on the front door tonight.

saying these in an interview costs you the question

  • Calls an embargo a legally binding agreement
  • Thinks the embargo protects users during the window
  • Treats the reporter as an attacker to be threatened
  • Says a silent patch is safer than an advisory
  • Asks for an open-ended embargo with no date

context

open as a page

How do you negotiate an embargo window with a reporter, and what happens when it expires?

level: middleimportance: must knowfreq 55%

basics

~20 s

Agree a specific calendar date early, justified by real engineering work rather than convenience. When the window expires the reporter is free to publish whatever they have, fix or no fix, so an unagreed overrun becomes full disclosure.

open as a page

Embargoed details leak from a distributor on day four. Do you publish immediately?

level: seniorimportance: should knowfreq 37%

basics

~20 s

Usually yes. An embargo is only worth keeping while the details are secret; once they circulate, holding protects the attackers' head start and nobody else. Confirm what leaked, tell every embargoed party the date has moved, then publish.

open as a page

Eleven downstream distributors want pre-notification of an embargoed flaw. How do you decide who gets it?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Pre-notify only parties who must rebuild and re-ship the affected code so their own users are protected on publication day. Operators who merely deploy it can wait for the advisory. Every extra recipient raises leak risk.

open as a page

One of six vendors cannot meet the agreed multi-party disclosure date. Do you extend for everyone?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Extending trades five vendors' users staying exposed longer against one vendor's users being exposed at publication. Decide against a rule agreed at the start: one short extension for a genuine engineering constraint, otherwise publish on the date.

open as a page