3 ms·
Not necessarily - see the recent bogus curl CVE's for instance. There's a lot of incentives to invent or embellish vulnerabilities for street cred or other reas
by xmodem 3y ago
Not necessarily - see the recent bogus curl CVE's for instance. There's a lot of incentives to invent or embellish vulnerabilities for street cred or other reasons.
Many years ago, a 'researcher' made claims to the media that our product had a zero-day that looked like a deliberate backdoor. They refused to tell us anything about the bug.
- dylan604 3y agoWhat kind of cred does the street give for making stuff up and posting about something that doesn't work? Seems like that would be one of those things where nature takes care of itself by weeding out these players.
- xmodem 3y agoAn embellishment can often be put down to a difference of opinion, and vendors have a reputation for downplaying vulnerabilities. In our case, the media reported the researcher's claims uncritically alongside our denials. We decided the best strategy was to say as little as possible, as saying or doing more wouldn't improve the quality of the reporting and would only risk drawing more attention to the false claims. I think we had a good track record of handling vulnerabilities well, and we definitely had some nasty ones. But this was not one of them.