Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How many people have the time or inclination to validate everything that way?


Not many, but the effort is parallelizable. If you find a security problem and report it in public, others can verify it, and still others can benefit from the fix even if they never would have bothered to look for themselves.


It doesn't take many. The problem is making sure that someone is doing it (cf., OpenSSL).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: