3 ms·
The thing is, code tends to be reused across projects. If you write a library or a utility program and it's full of holes, that's only OK if you're sure it will
by roca 5y ago
The thing is, code tends to be reused across projects. If you write a library or a utility program and it's full of holes, that's only OK if you're sure it will always be used in a "safe" context with no untrusted input. Who really wants to commit to that?
- eru 5y agoAlso, if you have a large enough corpus of random enough input, you are bound to hit similar bad cases as if you had some malicious input. More pithy: Hanlon's razor says 'never attribute to malice that which is adequately explained by stupidity.', but the reverse is also true: enough stupidity or just randomness can look like malice.
- GhettoComputers 5y agoAny non networked devices would be easy to commit to. Nobody will force you to use such a library if you are worried about holes. I think internet connected software like OS and browser matters, but I not only don't care if its in these devices, I WANT it to be easy to hack to run custom software. I am glad that the PSP had holes, I am happy camera firmware had holes, and I am also glad that android had holes, I never been hacked on it once, but I sure did hack it myself! The threat of most security issues is vastly overblown, spectre and meltdown don't exist in the wild, but they crippled all CPUs just in case. Security at what cost? I disabled it, I have no need to make my computer slower for a virus that will never affect me, I "wear" an updated browser. ;)