6 ms·
> Except there is lots to gain from being the first to write about the new malware on some registry Show me the company writing to their customers “we intentio
by teeray 4mo ago
> Except there is lots to gain from being the first to write about the new malware on some registry
Show me the company writing to their customers “we intentionally decided to ship code with potentially novel vulnerabilities. One of those vulnerabilities caused disclosure of your data, but cheer up! We have this cool security blog post about it now.” Meanwhile their competitors freeride and their customers’ data is safe.
- weaksauce 4mo agosecurity researchers not the ones shipping the faulty code.
- teeray 4mo agoWe’re not talking about security researchers here: > there is lots to gain from being the first to write about the new malware on some registry, so *companies* are actively downloading and inspecting literally every package. (Emphasis mine)
- john_strinlai 4mo ago>We’re not talking about security researchers here: we are. "companies" in this context is "security companies" (hence why they are "downloading and inspecting every package", which would not make sense if referring to the people authoring and shipping a single package)
- weaksauce 4mo agoyeah security researchers at security companies are the ones we are talking about.
- scheme271 4mo agoI think it's more some security company writing about a vulnerability they discovered in this module or a worm/backdoor and not the company that wrote the software. The security company gets publicity and potentially gets more biz for security consulting.