3 ms·
I find this hilarious in light of what we know about the NSA. All solid recommendations, but they are bandaids when compared to the sheer weight of capital that
by hyperion2010 10y ago
I find this hilarious in light of what we know about the NSA. All solid recommendations, but they are bandaids when compared to the sheer weight of capital that is being misused by hoarding known vulns. Unfunded mandates are fine for grandstanding.
- schoen 10y agoI strongly oppose vulnerability hoarding, but I'd point out that if we don't think it's easy to make political or cultural progress against it quickly, a technical alternative to make people safer is actually finding ways to make safe software. Plus, if "bugs are dense" advocates are right, we need major qualitative improvements to software development in order to make much of an impact (because they argue that different hoarders, or even different from-scratch researchers, would primarily know about different bugs). So it's not unreasonable for NIST (which actually wants people to enjoy computer security) to investigate what could be done in this area! Edit: but it's true that it would be awesome to see government do something to make these improvements actually happen -- and a research report probably isn't that.