←back to thread

1124 points CrankyBear | 1 comments | | HN request time: 0.261s | source
Show context
JamesBarney ◴[] No.45891454[source]
I get the idea of publicly disclosing security issues to large well funded companies that need to be incentivized to fix them. But I think open source has a good argument that in terms of risk reward tradeoff, publicly disclosing these for small resource constrained open source project probably creates a lot more risk than reward.
replies(5): >>45891546 #>>45891615 #>>45892029 #>>45892122 #>>45898765 #
1. phoronixrly ◴[] No.45892029[source]
You are missing the tiny little fact that apparently a large portion of infosec people are of the opinion that insecure software must not exist. At any cost. No shades of gray.