4 ms·
> * These things are bug-dependent, and the process that runs for a zero-interaction RCE won't be the same as the process that runs for a bug that requires a ma
by nopcode 5y ago
> * These things are bug-dependent, and the process that runs for a zero-interaction RCE won't be the same as the process that runs for a bug that requires a malicious app store app and only gives access to the contact database.
It would be interesting to understand at what point this becomes a GDPR issue, and if the GDPR legislation can be used to pressure companies in expediting this process.
- tptacek 5y agoThere's a "be careful what you wish for" argument here, because my understanding is that the FAANG vendors are snapping up security people just as fast as they possibly can, and, again, ceteris paribus you'd rather have those people working on the actual most serious vulnerabilities rather than the ones causing the noisiest bounty drama. But you could reasonably go either way on this I guess.
- jacquesm 5y agoThe degree of damage done by particular vulnerabilities is different from person to person. For one individual losing their contact database to some un-identified third party might be a 'meh' event, for another it could be a disaster.