3 ms·
Honest question: does this mean this vulnerability has been in bash for essentially its entire history and someone only discovered it now? Seems quite likely
by eah13 12y ago
Honest question: does this mean this vulnerability has been in bash for essentially its entire history and someone only discovered it now?
Seems quite likely that someone would have discovered it sooner, especially since it's so simple to exploit.
- patio11 12y agoEase of exploitation and ease of discovery have basically nothing to do with each other. Relatedly, "many eyes makes all bugs shallow" is, and always has been, totally horsepuckey. (And despite it being horsepuckey, and horsepuckey which is trivially exploitable in that if you believe it you'll produce software which can get owned by people who are better at e.g. counting to four than you are, people still believe it to this day.)
- gioele 12y ago> Relatedly, "many eyes makes all bugs shallow" is, and always has been, totally horsepuckey. Consider that the contraction of the more complete saying "Many eyes make bugs shallower than they would be if there were only few eyes".
- Tloewald 12y agoBut then there's the "Many eyes lead to a sense of complacency" issue -- like "No-one ever got fired for buying IBM|Microsoft|Blackberry"
- wglb 12y agoGiven that this is a 20 year old bug, that suggests that the number of eyes on this code were either zero or uninterested. Also, the BEAST bug was identified 20 years ago and nothing was done until Thai and Juliano caused a mild panic.
- robertgraham 12y agoThis has been there for nearly the entire history of Bash, like 2 decades.