A story of three kernel vulnerabilities
A story of three kernel vulnerabilities
Posted Feb 20, 2013 9:17 UTC (Wed) by epa (subscriber, #39769)In reply to: A story of three kernel vulnerabilities by spender
Parent article: A story of three kernel vulnerabilities
Yes, they took a biased sample. But that's the thing about security: you cannot rely on the law of averages to help you. An attacker only needs to be lucky once. If Trustwave can cherry-pick three vulnerabilities which took a long time to fix, an attacker can do the same. So it is quite legitimate to criticize the state of security fixes based on one security hole left unpatched, even if there were a thousand others fixed promptly.