3 ms·
Ah, I'm not sure I understand your last point. What about selling a "new high priced" item to the government because the engineering team spent some cycles fixi
by pointytrees 9y ago
Ah, I'm not sure I understand your last point. What about selling a "new high priced" item to the government because the engineering team spent some cycles fixing up the known vulnerabilities and re-released the product with those issues fixed. This seems like it would be more secure than a new untested product.
- endominus 9y agoThe argument is that companies would not fix the software, but instead release "new" products that don't have any "known" vulns. Basically, it would be cheaper to re-brand every year or two than spend the cycles to actually fix any bugs.
- yorwba 9y agoBut then any competitor could just find the old vulnerabilities in your "new" code and make them public. The re-branding effort would be completely wasted if you don't actually fix anything.
- thaumasiotes 9y agoFor one thing, if, as is likely, you try to fix a security vulnerability and fail, then you just fraudulently sold a product with a known vulnerability. When you release an untested product, you're safe.