Hacker News new | ask | show | jobs
by uola 3536 days ago
Sure, or if you find a way to find certain vulnerabilities quicker. A bug with 5 year life span that you can find in 1 month doesn't require you to find them too frequently and more projects that fixes such bugs in 1 year will also be vulnerable.

This is what I would assume someone like the NSA does. They would have calculated a window of where it's most advantageous for them to find a bug and will then spend the resources at that time. Both in terms of bug life time and severity, but also user share.