←back to thread

277 points jwilk | 1 comments | | HN request time: 0s | source
Show context
DeepYogurt ◴[] No.44382139[source]
It'd be great if some of these open source security initiatives could dial up the quality of reports. I've seen so so many reports for some totally unreachable code and get a cve for causing a crash. Maintainers will argue that user input is filtered elsewhere and the "vuln" isn't real, but mitre don't care.
replies(3): >>44382170 #>>44382407 #>>44382413 #
mschuster91 ◴[] No.44382170[source]
> I've seen so so many reports for some totally unreachable code and get a cve for causing a crash.

There have been a lot of cases where something once deemed "unreachable" eventually was reachable, sometimes years later, after a refactoring and now there was an issue.

replies(2): >>44382232 #>>44383832 #
DeepYogurt ◴[] No.44382232[source]
At what rate though? Is it worth burning out devs we as a community rely upon because maybe someday 0.000001% of these bugs might have real impact? I think we need to ask more of these "security researchers". Either provide a real world attack vector or start patching these bugs along with the reports.
replies(2): >>44382273 #>>44382336 #
mschuster91 ◴[] No.44382336{3}[source]
IMHO, at least the foundations of what makes the Internet tick - the Linux kernel, but also stuff like SSL libraries, format parsers, virtualization tooling and the standard libraries and tools that come installed by default on Linux systems - should be funded by taxpayers. The EU budget for farm subsidies is about 40 billion euros a year - cut 1% off of it, so 400 million euros, and invest it into the core of open source software, and we'd get an untold amount of progress in return.
replies(2): >>44382828 #>>44384416 #
charcircuit ◴[] No.44382828{4}[source]
It's not the government's job to subsidize people's bad business models.
replies(2): >>44385380 #>>44387657 #
1. viraptor ◴[] No.44387657{5}[source]
It shouldn't be, but it is to a huge degree. Oil companies, corn production, milk subsidies, road network growth, etc. are all bad business subsidies in the US for example.