|
|
Log in / Subscribe / Register

A fuzzy issue of responsible disclosure

A fuzzy issue of responsible disclosure

Posted Aug 15, 2022 11:56 UTC (Mon) by mcatanzaro (subscriber, #93033)
In reply to: A fuzzy issue of responsible disclosure by jan.kara
Parent article: A fuzzy issue of responsible disclosure

This entire discussion feels a little ridiculous. Why are we questioning the motivations of people who are reporting security bugs? Money, fame, an integer value in an academic paper... who cares? A report from a fuzzer is a gold standard bug report. If it's NOT reported, attackers are going to find it anyway... often by using the exact same fuzzers!

The quantity of bugs reported by researchers running fuzzers is proportional to the quantity of bugs in the code. Want fewer bug reports? Write better code. (Easier said than done, I know.)

Meanwhile, in somewhere userspace: WebKit does not have time to address all the fuzzer reports we receive, and our users are less safe for it. But we certainly do not complain that they're reported.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds