Earlier quoted context omitted.
> really basic things like updating OpenSSL libraries seem near impossible for Huawei. > Huawei (...) took their designs and code, without fully understanding them. Do you want to say that there aren't people in China smart enough to "update OpenSSL" in their codebase? Whichever way the codebase started to be used by the company? A lot of companies and developers inherit the products created in some other times in so…
Many companies have the same problems, not rewarding people who fix these type of security issues and look at security holistically, and instead the only path to success is to create new features
It is rotten corporate culture that is starving critical maintenance work at these companies, creating the internet of vulnerable shit.