OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: [Dailydave] Lame studies that people quote as fact that haveno basis in reality and still don't prove anything even if they did

From: Chris Eagle (cseagleredshift.com)
Date: Wed Feb 04 2004 - 19:44:55 CST


Matt wrote:
> > I also think they were referring more towards cases in which new
> > functionality needs to be added to existing code, or existing
> > functionality modified to some significant degree. Vulnerabilities
> > don't tend to fall into either of these categories.
>
> Are you for real? How do you define vulnerability?
>

Neither of the above imply the software is broken while a vulnerability
does. Software can a) get redesigned or b) have features added without c)
discovering or repairing any vulnerabilities. Both a and b are probably more
expensive than c.

Chris