3 ms·
No one knows how many vulnerabilities there are in closed source medical record software - because we can't check. There are _probably_ loads though, because th
by dflock 5mo ago
No one knows how many vulnerabilities there are in closed source medical record software - because we can't check. There are _probably_ loads though, because that medical software is super terrible in every way that we _can_ check.
- oatmeal1 5mo agoOr voting machines.
- mixedmath 5mo agoI wasn't aware that there were any public, commonly-used voting machines that we could check.
- 0xdeadbeefbabe 5mo agoSQL injection and XSS come up in dynamic analysis too.
- 1970-01-01 5mo agoIsn't anything closed-source by definition this? Why speak of the subset of closed-source medical record software when it's just the entire class of software?
- nradov 5mo agoWell the closed-source EHR applications that use NoSQL databases such as MUMPS (InterSystems Caché) probably don't have many SQL injection vulnerabilities.