3 ms·
It's about increasing the costs to the attacker. Now a Windows/browser zero-day requires months of research and can be sold for $100k+.
by 21 8y ago
It's about increasing the costs to the attacker.
Now a Windows/browser zero-day requires months of research and can be sold for $100k+.
- est31 8y agoYes, the goal is to increase the costs to the attacker as much as possible while having minimal added costs during development and runtime of the software. Statically proven programs are great security wise but they are expensive to produce, while adding ASLR is not perfect but comparatively easy to pull off.