|
|
|
|
|
by danielbarla
3537 days ago
|
|
Good point. Though without perfect hindsight (or looking at any given time), it's certainly possible that there are entire categories of privately known vulnerabilities which are not even on the public radar. So it's quite possible that the rate at which known vulnerabilities are fixed might be very misleading. I guess they would offer a good base for the discussion nevertheless. |
|
This is what I would assume someone like the NSA does. They would have calculated a window of where it's most advantageous for them to find a bug and will then spend the resources at that time. Both in terms of bug life time and severity, but also user share.