Dailydave mailing list archives

RE: Lame studies that people quote as fact that haveno basis in reality and still don't prove anything even if they did


From: "Chris Eagle" <cseagle () redshift com>
Date: Wed, 4 Feb 2004 17:44:55 -0800

Matt wrote:
I also think they were referring more towards cases in which new
functionality needs to be added to existing code, or existing
functionality modified to some significant degree. Vulnerabilities
don't tend to fall into either of these categories.

Are you for real? How do you define vulnerability?


Neither of the above imply the software is broken while a vulnerability
does. Software can a) get redesigned or b) have features added without c)
discovering or repairing any vulnerabilities. Both a and b are probably more
expensive than c.

Chris

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://www.immunitysec.com/mailman/listinfo/dailydave


Current thread: