logoalt Hacker News

traceroute66yesterday at 9:01 PM1 replyview on HN

But why should insecure argument handling bugs (as per your recent SSH bulletin) be found after release ?

Those are an ancient class of bugs that should be picked up by any competent security review.


Replies

apenwarryesterday at 9:05 PM

Is your theory that "any competent security review" will find every security hole in a product? Because that sure would be great if it were true. Unfortunately it does not match my experience.

show 2 replies