← Back to context

Comment by WrtCdEvrydy

4 years ago

Yes, and robbing a bank to show that the security is lax is totally fine because the real criminals don't notify you before they rob a bank.

Do you understand how dumb that sounds?

> Do you understand how dumb that sounds?

If you make a dumb analogy, that's on you.

  • Same analogy... there's a vulnerability and you want to test it? Go set up a test, and notify the people.

    You really think the Linux kernel guys would change their process if you did this? They'd still do the same things they do.

    • > Go set up a test, and notify the people.

      The vulnerability is in the process, and this was the test.

      > You really think the Linux kernel guys would change their process if you did this? They'd still do the same things they do.

      If they're vulnerable to accepting patches with exploits because the review process fails, then the process is broken. Linux isn't some toy, it's critical infrastructure.

      6 replies →