Vulnerability Research - HP Changes TippingPoint ZDI Disclosure Policy - eWeek Security Watch

HP Changes TippingPoint ZDI Disclosure Policy

Written By
Brian Prince
Brian Prince
Aug 4, 2010
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

HP announced changes today to the disclosure policy for its TippingPoint Zero Day Initiative (ZDI).

Henceforth, the company will publish vulnerability advisories no later than six months after flaws are detected and submitted to the program. According to HP, the idea is to make sure vendors fix vulnerable software quickly to reduce the risk of potential attacks.

The advisories will feature “limited details” of the vulnerabilities to enable users to take precautions, the company said in a statement.

The change follows a move by Mozilla and Google to increase the bounty paid for bugs. For Mozilla, the new max is $3,000; for Google, it’s $3,133.70. It also follows more members of Microsoft’s attempt to change perceptions around responsible disclosure by changing the term to “coordinated vulnerability disclosure.”

While vendors may grunt disdainfully at the idea of a timeline, Aaron Portnoy, manager of Security Research for TippingPoint, noted vendors can be less than punctual if left to their own devices.

“As it stands right now there are currently 31 high-risk vulnerabilities reported by the ZDI over a year ago that are awaiting a patch from the vendor,” he blogged. “We believe this places the end user unnecessarily at risk for an extended period of time.”

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.