Hot take: the cybersecurity industry wastes an incalculable amount of effort "remediating vulnerabilities" in code because a library used has some "vulnerability" that can't actually be exploited in the way it's used in the application.
Conversation
Notices
-
Embed this notice
Jake Williams (malwarejake@infosec.exchange)'s status on Thursday, 26-Dec-2024 23:41:50 JST Jake Williams -
Embed this notice
silverwizard (silverwizard@convenient.email)'s status on Thursday, 26-Dec-2024 23:41:50 JST silverwizard @malwarejake is triaging a vulnerability report easier than upgrading the library to a non-vulnerable version, especially if there's going to need to be future upgrades?
-
Embed this notice