3 ms·
Don't attribute to malice what could easily be attributed to stupidity. I'm no fan of pitchforks, and I don't doubt plenty of people might make this mistake. B
by egocodedinsol 10y ago
Don't attribute to malice what could easily be attributed to stupidity.
I'm no fan of pitchforks, and I don't doubt plenty of people might make this mistake. But lots of malicious actors hide behind this response.
- throwaway91111 10y agoPerhaps we should just avoid drawing any conclusions about intent from a single line of code.
- egocodedinsol 10y agoYes. Although I suppose the probability you're a malicious actor given that you've produced a vulnerability rise substantially (though still remains quite small).
- djrogers 10y ago> I suppose the probability you're a malicious actor given that you've produced a vulnerability rise substantially That's ridiculous on it's face - all software has vulnerabilities, and not all malicious actors produce vulnerabilities. Heck, the vast majority of malicious actors don't even discover vulnerabilities, they simply exploit them.
- apendleton 10y agoYou omitted the parenthetical "(though still remains quite small)," which was important. I think the point was: if you were (miraculously, in your view) to produce a piece of software that was free of vulnerabilities, I could safely conclude that you weren't trying to maliciously produce vulnerable software. If you instead produced a piece of software that contained vulnerabilities, it would at least be possible that you were such a malicious actor, so the probability would be higher, if still very small (small-but-nonzero vs. zero).