Hacker News new | ask | show | jobs
by scarface74 3371 days ago
In theory yes, but just to take one well known example, the HeartBleed SSL bug was introduced in 2012 but wasn't found until 2014.
1 comments

At least it can be patched, if the equivilent bug occured in a closed source arm SoC driver, it would NEVER be patched.
Why wouldn't it be? If a vendor doesn't patch their drivers to fix security issues, people will stop using their products.