3 ms·
"because there is virtually no quantifications of risks in anything I've read on the results of security research" Nearly all results of security research are
by sprkyco 11y ago
"because there is virtually no quantifications of risks in anything I've read on the results of security research"
Nearly all results of security research are given at least some metric for risk quantification. https://cve.mitre.org https://cve.mitre.org is a single example of an attempt to quantify risk. I'm assuming at least at some point you have run across these numbers so the statement is patently false or a complete exaggeration.
- sago 11y ago> so the statement is patently false or a complete exaggeration. Oh, don't misunderstand me, it could very well be either. I'm not claiming to have discovered this based on extensive knowledge. Thanks for the link. So the CVSS metric is the one you're referring to? I've not seen that mentioned in vulnerability reports, no. Once again, more than happy to admit this is my failure or lack of diligence to notice. But when I've asked before about quantification, I've typically only got variants of 'you must take all vulnerabilities totally seriously, because the bad guys are powerful and evil.'
- mike_hearn 11y ago> But when I've asked before about quantification, I've typically only got variants of 'you must take all vulnerabilities totally seriously, because the bad guys are powerful and evil.' The CVE system is something used (mostly) by professionals who deal with the security/usability/performance/cost/etc tradeoff every day. It makes sense that they do quantify risk. You see this all the time when MS/Google/Apple etc decide whether to patch an issue or not. Random security "experts" on internet forums are not like that. Many are amateurs with an interest in the topic but they don't work on any major products and so have never had to be faced directly with those other costs. So of course they assume that security is the be all and end all, and nothing else is more important. But you get that in every walk of life. Ditto with cryptographers and privacy.