3 ms·
> Distinguishing between a simple bug and a vulnerability requires contextual knowledge and expert judgement that simply cannot be built into bureaucratic organ
by derstander 3y ago
> Distinguishing between a simple bug and a vulnerability requires contextual knowledge and expert judgement that simply cannot be built into bureaucratic organisations like MITRE.
Why can’t it? MITRE runs FFRDCs. Having worked for an FFRDC (although in electrical engineering, not computer security), if you were to tell me that engineers in FFRDCs or UARCs in my domain simply cannot utilize contextual knowledge or expert judgment (or that their knowledge and judgment would be completely overridden by management such that it appears they can’t) then I would wonder if you ever interacted with that kind of organization.
Is computer security somehow different to e.g. radar or comms systems engineering?
- LudwigNagasena 3y agoThe scope of use is very underspecified. If your program is disconnected from the internet, all remote execution bugs stop being security bugs. If you can provide specific input to run arbitrary code into a program that already requires you to have elevated privileges to run, it is not a security bug. Etc, etc.
- derstander 3y agoSorry: I'm confused. Are you saying this is why an organization like MITRE cannot build contextual knowledge and expert judgement into itself? Or are you saying this is how computer security differs from radar and/or communications systems engineering?
- LudwigNagasena 3y agoBoth?