OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Dailydave] Lame studies that people quote as fact thathaveno basis in reality and still don't prove anything even ifthey did

From: Matt Hargett (mattuse.net)
Date: Wed Feb 04 2004 - 19:37:40 CST


> Matt wrote:
> > > I also think they were referring more towards cases in which new
> > > functionality needs to be added to existing code, or existing
> > > functionality modified to some significant degree. Vulnerabilities
> > > don't tend to fall into either of these categories.
> >
> > Are you for real? How do you define vulnerability?
> >
>
> Neither of the above imply the software is broken while a vulnerability
> does. Software can a) get redesigned or b) have features added without c)
> discovering or repairing any vulnerabilities. Both a and b are probably
more
> expensive than c.

I'm sorry, I thought you were implying that architectural and/or
implementation vulnerabilities in existing code aren't introduced (knowingly
or unknowingly) with refactoring or feature adds. I must've misunderstood
what you were saying. Thanks for the clarification.