3 ms·
You’ll find more primary sources across different organizations that all arrive at the 60 - 70% number. But what really grinds my gears here is that you take a
by znkr 3y ago
You’ll find more primary sources across different organizations that all arrive at the 60 - 70% number. But what really grinds my gears here is that you take a piece from the article you’re criticizing and pretend that it’s a quote from Matt Miller.
It’s actually quite easy to find a primary source here because the slides from the talk that the article is based on are available: https://github.com/microsoft/MSRC-Security-Research/blob/master/presentations/2019_02_BlueHatIL/2019_01%20-%20BlueHatIL%20-%20Trends%2C%20challenge%2C%20and%20shifts%20in%20software%20vulnerability%20mitigation.pdf https://github.com/microsoft/MSRC-Security-Research/blob/mas...
To quote from those slides: „~70% of the vulnerabilities addressed through a security update each year continue to be memory safety issues“.
- andrewstuart 3y agoYou didn’t read the linked article. It directly attributes Matt Miller. And the point is that this percentage quoted is the flaws in Microsoft products, not all security vulnerabilities as is falsely claimed.
- znkr 3y agoIt’s an indirect quotation, not a quote from a primary source. Your quotation is a quotation of the article, not of Matt Miller. Read the primary sources, the misunderstanding is yours.