Looking for sources for the Google security funding led me to rediscover the eye-wateringly inaccurate reporting around Heartbleed. For example: https://www.zdnet.com/article/heartbleed-open-sources-worst-hour/ …. Heartbleed was not even the worst bug in OpenSSL, let alone in all of open source.
-
Pokaż ten wątek
-
Linux has far worse bugs on a regular basis. There are libraries in extremely wide use that are so full of bugs it isn't even funny. But where are the headlines about those?
5 odpowiedzi 3 podane dalej 11 polubionychPokaż ten wątek -
-
W odpowiedzi do @kooky_uk
Pay people to fix bugs. You can get $1M for a zero day. Can you get $1M to fix a zero day? Fuck no. Why would anyone want them fixed? A huge sector of the IT "industry" (I use the term loosely) makes a fortune from bugs - and not by fixing them. This is obviously wrong.
3 odpowiedzi 3 podane dalej 3 polubione -
W odpowiedzi do @BenLaurie @kooky_uk
Fixing bugs seem to be of higher value than the actual writing of the software that contain them.
1 odpowiedź 0 podanych dalej 0 polubionych
One would think, however almost no company pays developers to fix them for most open source projects, they pay developers to add new features.
Wydaje się, że ładowanie zajmuje dużo czasu.
Twitter jest przeciążony lub wystąpił chwilowy problem. Spróbuj ponownie lub sprawdź status Twittera, aby uzyskać więcej informacji.