> If a security vulnerability is reported by someone who is also violating the CoC, what do you do? Do you ignore it? Fix it silently? Is this even a question? You triage and fix the vulnerability just like any other one. Are truths spoken by folks one dislikes — even for perfectly valid reasons — any less true? The only way I can imagine this somehow applying is if someone has a habit of reporting vulnerabilities wh…
Vulnerability reports are not special anymore
11–20 of 249 posts
Re: Vulnerability reports are not special anymore
#12Re: Vulnerability reports are not special anymore
#13Security through obscurity was never a great strategy.. and now it’s not a strategy at all.. Hopefully at the end of this decade, a ton of software practices have been overhauled to eliminate classes of problems. Memory-safe language use is a great start - but it’d be great to see innovation in checking for TOCTOU problems, improper/missing authn & authz, and many others. This is an engineering problem. It won’t be s…
Verifying correctness of an implementation is P NP, not serious CS research.
Personally i have some doubts, a lot of research has gone into the idea without much to show for it, but its a very reasonable research area.
Re: Vulnerability reports are not special anymore
#14Security through obscurity was never a great strategy.. and now it’s not a strategy at all.. Hopefully at the end of this decade, a ton of software practices have been overhauled to eliminate classes of problems. Memory-safe language use is a great start - but it’d be great to see innovation in checking for TOCTOU problems, improper/missing authn & authz, and many others. This is an engineering problem. It won’t be s…
Verifying correctness of an implementation is P NP, not serious CS research.
Re: Vulnerability reports are not special anymore
#15Re: Vulnerability reports are not special anymore
#16Re: Vulnerability reports are not special anymore
#17Re: Vulnerability reports are not special anymore
#18It’s tough staying motivated on a craft when an AI is nearly as good as you. Chess players manage to do it at least.
Re: Vulnerability reports are not special anymore
#19Security through obscurity was never a great strategy.. and now it’s not a strategy at all.. Hopefully at the end of this decade, a ton of software practices have been overhauled to eliminate classes of problems. Memory-safe language use is a great start - but it’d be great to see innovation in checking for TOCTOU problems, improper/missing authn & authz, and many others. This is an engineering problem. It won’t be s…
Re: Vulnerability reports are not special anymore
#20Tangent point, I think more broadly this is a big piece of AI-cynicism in general- “x isn’t special anymore”. It’s tough staying motivated on a craft when an AI is nearly as good as you. Chess players manage to do it at least.
The 5 on earth still getting paid to play chess?