Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I believe standard procedure would be for IRS to report it to US-CERT who are part of the Department of Homeland Security.


I believe standard procedure would be for IRS to report it to US-CERT who are part of the Department of Homeland Security.

At which point (I imagine), decisions would be made along the same lines as I described, the key questions being "can we keep it secret?" and "who has this capability?".

I tried to be nation-agnostic, as I imagine there may be a bit of difference in how a given nations' intelligence agency weighs the value of their offensive capabilities and the public defensive capabilities in light of who knows about the bug.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: