Re: Re: fucking chinese ballo
By: MRO to esc on Sun Feb 12 2023 02:49 pm
Where were these people those 2 years that heartbleed was in the code and being exploited ;)
For every example of an open source vulnerability that went undetected for years, a cursory google search can give you an example of a closed-source vulnerability that went undetected for years, too.
For example, EternalBlue was a Windows exploit that the NSA knew about for at least 5 years. It existed as far back as Windows XP, and even caused Microsoft to release patches for those ancient, unsupported operating systems once it was publicly disclosed in 2017.
The problem with Windows and many closed source systems is that people still refuse to update them in a timely manner. The WannaCry ransomware attack was incredibly succesful because systems weren't patched.
Network devices often rely on closed source firmware, and they're notoriously difficult to update, as it requires shutting the network device down to reboot it, so people simply don't update it. There are probably a handful of Cisco routers out there that haven't been updated in 20+ years.
Most studies that have been done about security vulnerabilities have shown no appreciable difference between open source and closed source software. They're both affected by security flaws at the same rate.
DaiTengu
...He's dead Jim. You take his phaser, I'll take his wallet!
---
þ Synchronet þ War Ensemble BBS - The sport is war, total war - warensemble.com