4 ms·
> Did they need to do all the extra work of developing an exploit in order to convince someone that was dangerous? It might be clear in this case for someone w
by funcDropShadow 3y ago
> Did they need to do all the extra work of developing an exploit in order to convince someone that was dangerous?
It might be clear in this case for someone who has already seen that really obscure bugs could be practically misused. But in the long-term, it is necessary to show that this is not some theoretical risk, which could be exploited in one never-heard-of hobby linux distribution. If security researchers skip these PoCs, a generation of future developers - who never saw practical PoCs - will just not believe it is relevant.
Saying the security researchers don't need to show PoCs is like saying mathematicians don't need proof, they just need to be very sure that a theorem holds.
That is the difference between a researcher/scientist and an engineer. An engineer could say, well this is likely exploitable, therefore let's safeguard against this. So that there remains a margin of security.