3 ms·
If I lost $1 for each time I left a known vulnerability unpatched because I was convinced I had more important work to do, I would be a very poor man indeed. H
by tjarratt 16y ago
If I lost $1 for each time I left a known vulnerability unpatched because I was convinced I had more important work to do, I would be a very poor man indeed.
Honestly, there are very very few developers that fix security problems in beta environments before anything else. In my experience, it's more likely that you're fighting fires, handling outages, and dealing with problems of scale than fixing security vulnerabilities.
Besides, isn't a beta the correct time to find these security issues? (Design / Alpha would be the ideal time, granted, but sometimes that's not possible.)